10-12-2018 01:44 AM - edited 10-12-2018 01:46 AM
Hi all,
yesterday we recieved RMA-ed Cisco ESA C370 which came with version 7.1.5 -104 and i decided to upgrade to a 8.0.1 version ( this was the latest version available). After the upgrade i'm unable to login into device. The error i'm recieving is:
"AsyncOS 8.0.1 for Cisco IronPort C370 build 023
Welcome to the Cisco IronPort C370 Messaging Gateway(tm) Appliance
ERROR: "'displayalerts'" is not in the permissions dictionary in the config file system.users/data.cfg.
Please re-update your configuration files. "
and after a few attpemts to log in , getting this error:
AsyncOS 8.0.1 for Cisco IronPort C370 build 023
Welcome to the Cisco IronPort C370 Messaging Gateway(tm) Appliance
ERROR: "'outbreakconfig'" is not in the permissions dictionary in the config file system.users/data.cfg.
Please re-update your configuration files.
I have ping to device, but not SSH and WEB. Only console is working. Any ideas what to do ?
10-12-2018 02:26 AM
If this is a production and you have service outage, raise a TAC case as P1 to investigate and fix as soon as possible.
10-12-2018 02:30 AM
This is a RMA device send from Cisco and It's in lab environment now, because i need to upgrade it to 11.0.0 version and then to replace the production device.
10-12-2018 02:49 AM
So can you explain more to assists here.
what is the the production verison, and what is the backup config taken from which version ?
10-12-2018 02:54 AM
10-12-2018 03:34 AM
Here is steps you need to follow to upgrade and put back in to production.
You can do an initial configuration using the setup wizard to get your IP address and hostname configured so you have network access, or you can simply connect to 192.168.42.42 and log in as admin to start the upgrade on the replacement appliance.
Notes:
Instructions:
1) Save the configuration from the old appliance to your local machine. From the GUI -> System Administration -> Configuration File -> Download file to local computer to view or save. Be sure to un-check the box “Mask passwords in the Configuration Files”.
2) Get the new appliance up and running on your network. For access by Ethernet, connect to the Management Network Port. Use a browser to access the web-based interface on the default IP address 192.168.42.42 (username: admin, password: ironport). You can also access the command line interface by SSH or terminal emulation software on the same IP address. (The netmask is /24). For Serial access, connect to the Serial Port. Access the command line interface by a terminal emulator using 9600 bits, 8 bits, no parity, 1 stop bit (9600, 8, N, 1), flowcontrol = Hardware.
Run the system set up wizard (SSW). If your old appliance is dead or already off the network, then you can use the same IP information. If your old appliance is still on the network, then give the new appliance a temporary IP address (which has internet access to get updates).
3) Check to make sure the new appliance is on the same version and build of AsyncOS. From the GUI -> Monitor -> System Status. If they are the same, move on to step 5. If they are not the same, continue to step 4.
4) If the appliances are not on the same build, upgrade the new appliance to match the version of the old one. From the GUI -> System Administration -> System Upgrade -> Available Upgrades. If you see it in the list, please select it. If it is not listed, the specific version may need to be provisioned by Cisco IronPort Customer Support - please call before proceeding.
Note: If the old appliance is at a version that is older than the replacement appliance, you will need to upgrade it (if possible) to match the new appliance.
Some case you will not able to get updates due to some issue, make sure cisco register this device in their inventory to get updates. - if keep failing you need to contact cisco TAC for this.
5) Once the appliances are verified to be at the same version, load the configuration file to the new appliance. From the GUI -> System Administration -> Configuration File -> Load a configuration file from local computer.
6) If the configuration file loads without any errors, then you can proceed to decommission the old appliance and edit the IP settings of the new appliance as desired. From the GUI -> Network -> IP Interfaces. You may also need to edit the routing information as well (Network -> Routing).
7) If you get any errors when loading the new configuration file, you can try and edit the configuration file with an XML editor and look for the section that the error refers to. However, if you are not comfortable with this, please call in for support.
compare the config and you happy with the configuration, put the ESA in to production under change/maintenance windows and do some test, keep monitor until it stable and working as expected in the working environment.
10-12-2018 03:41 AM
10-12-2018 05:06 AM
Ok, but how to perform factory reset of the config, when i cannot login .. ?
10-12-2018 05:43 AM
10-12-2018 06:02 AM
As per your description we are impression, you have access to device.
Only console is working - if so below document will help you to reset to factory.
You do not have access console login also, then open TAC for the same.
10-12-2018 06:10 AM
Yes i have console connection to the device, but i'm stucked on login phase, so i cannot execute commands, that's why i cannot perform factory reset. Is there a way, by pressing a button to reset it ? I'm really frustrated, that cannot find Hardware Guide for this platform.
10-12-2018 06:21 AM
Suggest to raise an a TAC case to resolve soon.
10-14-2018 11:23 PM
Ook, thank you. I will open a case and will update here.
10-17-2018 06:47 AM
Problem solved - new RMA.
10-18-2018 01:52 AM - edited 10-18-2018 01:58 AM
Hello again, i'm trying to upgrade the NEW device to version 11.0.0-105 LD from 10.0.0-203 ( i checked the release notes and it says that i can upgrade from my version to 11.0.0-105) but from the available upgrades i don't see it. Why is that ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide