Security

last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass test/dev instance from production cluster

This thread has been viewed 0 times
  • 1.  ClearPass test/dev instance from production cluster

    Posted Aug 04, 2017 07:15 PM

    We have a 5 server CP production cluster.  We have a test instance that consists of a single node into which we've imported the production config and logs.

     

    This has worked well to allow me to try potential changes from the production configuration, but I would like to be able to test the new patch 7 before applying it to production.  The problem is that importing the production config into the test instance means that the other members of the cluster were carried over and the patch fails to apply:

    ERROR: Cluster nodes are not in sync. Ensure all nodes in cluster are in sync and retry.
    ERROR: Patch update will be aborted. Exiting..

     

    This makes some sense in that the other members of the cluster appear to be down, but it prevents me from testing the patch outside production.

     

    It appears that I might be able to delete the other cluster subscribers though the deletion process actually contacts the subscriber and requests it to drop itself - thankfully the subscriber doesn't recognize the test CP as its publisher so it refuses.  I then tried to delete the backup publisher but it refuses because it is part of the Virtual IP definition.  I don't feel comfortable changing those settings because that could potentially interfere with the production publishers which could be catastrophic.

     

    Is there any way to import the configuration from a production CP cluster into a singular CP test instance in such a way that I will be able to install the patch?

     

    The only idea I have left at this point which seems pretty tedious would be to wipe the test CP, build it from scratch and install patch 7 and then import the production CP configuration.  I'm a little worried that the configuration will refuse to import because the versions will be different.

     

    Hints, suggestions, or actual experience would be most appreciated.



  • 2.  RE: ClearPass test/dev instance from production cluster

    Posted Aug 07, 2017 09:29 AM

    What we did with our test box was to join it as a subscriber to our production cluster and then removed it from the cluster. The test box then had the production config.



  • 3.  RE: ClearPass test/dev instance from production cluster

    Posted Aug 17, 2017 06:29 PM

    Sorry, shouldn't have left this alone so long.

     

     

    Maybe there is more to your picture that you didn't describe, but I wonder if your test instance carried with it additional members of the cluster because that is what stymied me from testing the next patch.  It seems pretty hard to get them out of the config on the test system.



  • 4.  RE: ClearPass test/dev instance from production cluster

    Posted Aug 21, 2017 04:26 PM

    In our case after removing the test box from the cluster no other production subscriber or publisher information was carried over but the services and other config was the same as production.



  • 5.  RE: ClearPass test/dev instance from production cluster

    Posted Aug 21, 2017 03:30 PM

    Why not building a VM with same exact image as your prod but never join it to the cluster and load a config backup on it, then upgrade it ?