Security

 View Only
last person joined: 9 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

clearpass fails auto backups

This thread has been viewed 57 times
  • 1.  clearpass fails auto backups

    Posted Sep 09, 2021 02:44 AM
    Hi!

    Im trying to setup auto backups to a linuxserver over sftp. If I use the account manually in a terminal over sftp it works just as expected.
    However when clearpass runs its auto backups nightly it fails with this error message:

    Transfer Type: SFTP

    Reason: [Errno 2] No such file


    I've tried creating 2 folders in the user root named with the servers ip adresses:
    Like this:

    1.1.1.1
    1.1.1.2

    clearpass is 6.9.4


  • 2.  RE: clearpass fails auto backups

    MVP EXPERT
    Posted Sep 09, 2021 04:01 AM
    I've seen this fail if a Remote Directory is not specified as part of the File Backup Servers within CPPM. Have you specified one?

    ------------------------------
    Craig Syme
    ------------------------------



  • 3.  RE: clearpass fails auto backups

    Posted Sep 09, 2021 04:25 AM
    I was using / before.
    Going to test /backups tonight. I'll get back to you.



  • 4.  RE: clearpass fails auto backups

    MVP EXPERT
    Posted Sep 09, 2021 04:29 AM
    Sounds good, let us know the outcome.

    ------------------------------
    Craig Syme
    ------------------------------



  • 5.  RE: clearpass fails auto backups

    EMPLOYEE
    Posted Sep 09, 2021 05:54 AM
    Make sure that the directory /backups exists, and is writable for the configured user...

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 6.  RE: clearpass fails auto backups

    Posted Sep 10, 2021 02:45 AM
    sadly I got the same error again.
    The folders have the correct permissions and I've tested sftp manually using the same account without any issues.
    EDIT: The username is backup_clearpass



  • 7.  RE: clearpass fails auto backups

    EMPLOYEE
    Posted Sep 10, 2021 08:14 AM
    You screenshot shows /home/sftp/backup_clearpass/backups/
    Is that the path that you are in if you do a cd /backups in the sftp session??

    If it is not, you can try to enter backups as the path, or ./backups/, or the full path /home/sftp/backup_clearpass.

    In my lab, I have the full path: /home/cpbackup/clearpass-backups/ (and with a trailing /), user is cpbackup.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 8.  RE: clearpass fails auto backups

    Posted Sep 10, 2021 09:12 AM
    my sftp conifg connects the user to their homedir on connection. So this is image below is the view using the actual account (above was from ssh user so sorry for the confusion).




  • 9.  RE: clearpass fails auto backups

    EMPLOYEE
    Posted Sep 13, 2021 03:45 AM
    Would not understand why it doesn't work. Think it is time to open a Support case, if you can't see anything in the sftp server host logs.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 10.  RE: clearpass fails auto backups

    Posted Sep 13, 2021 04:29 AM
    Ok will do.
    sshd logs shows no errors all seems fine.
    shows:   accept password -> open  -> closed


  • 11.  RE: clearpass fails auto backups

    EMPLOYEE
    Posted Sep 14, 2021 04:14 AM
    You could try adding the folder with CPPM IP under the "backups" directory on Linuxserver with backup_clearpass as the owner.
    And update the CPPM filepath with full path like "/home/user/backups/CPPMIP" instead of "/backups/.


    /home/nick/backup/10.23.194.221 ( Directory path )



    ------------------------------
    SANDEEP YADAV
    Global Escalation Center, ACCP | Aruba Software
    ------------------------------



  • 12.  RE: clearpass fails auto backups

    Posted Sep 15, 2021 08:40 AM
    We have the same issue on 6.9.   Noticed it a year ago.  Support says it is a known issue and it is fixed in 6.10.   I however have end of life CPPM servers that do not support 6.10 so I have not been able to correct.  New servers coming Q1 2022 for me.   If you can get to 6.10 please let me know if it helps.

    ------------------------------
    Alan Scott
    ------------------------------



  • 13.  RE: clearpass fails auto backups
    Best Answer

    Posted Sep 21, 2021 06:01 AM
    Hi!

    Haven't been able to update to 6.10 just yet. So it looks like it might have been a bug with sftp.
    I changed to scp and wrote to home directory of user (using . sign) . After doing this clearpass automatically created a dir for each server in cluster and wrote backups to it without any issues.