Security

 View Only
last person joined: 8 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass 6.11 stopping services during update installation

This thread has been viewed 33 times
  • 1.  ClearPass 6.11 stopping services during update installation

    Posted Mar 16, 2023 05:10 AM

    Hi

    While updating ClearPass 6.11 I have noticed a new behaviour during the installation. In previous versions all services have been running during the installation of any updates or upgrades. 

    With version 6.11 several services are stopped during the installation of the updates. As far as I can see in the documentation for 6.11 this behaviour change isn't mentioned anywhere. The services remain stopped after successful installation until the server reboots. Is this a new behaviour we should expect in ClearPass 6.11 or is it an unintentional action to stop the services during update installation.

    Output from the CLI comman service status all:
    Policy server [ cpass-policy-server ] is running
    TACACS+ Server [ cpass-tacacs-server ] is stopped
    Radius server [ cpass-radius-server ] is running
    Async DB write service [ cpass-dbwrite-server ] is stopped
    DB replication service [ cpass-replication ] is stopped
    DB change notification server [ cpass-dbcn-server ] is stopped
    System monitor service [ cpass-sysmon-server ] is stopped
    System auxiliary service [ cpass-system-auxiliary-server ] is stopped
    Admin server [ cpass-admin-server ] is running
    Async netd service [ cpass-async-netd ] is running
    Zone cache [ cpass-zone-cache-server ] is running
    Stats collection service [ cpass-statsd-server ] is running
    Stats aggregation service [ cpass-carbon-server ] is running
    Ingress logger service [ cpass-igslogger-server ] is stopped
    Ingress logrepo service [ cpass-igslogrepo-server ] is stopped
    RadSec Service [ cpass-radsec ] is stopped
    Grafana server [ grafana-server ] is running
    AirGroup notification service [ airgroup-workqueue ] is stopped
    ClearPass Guest background service [ cpg-background ] is stopped
    ClearPass Guest cache [ cpg-redis-cache ] is stopped
    Extensions service [ cpass-extensions ] is running
    Micros Fidelio FIAS [ fias-server ] is stopped
    ClearPass Virtual IP service [ cpass-vip ] is stopped
    ClearPass IPsec service [ cpass-ipsec ] is stopped

    I have always informed the customers that the installation will only cause a short service disruption during the reboot of the server. Now the disruption will be prolonged as some services are stopped during the installation.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP 2023, ACCX #1335, ACMP, ACDP, ACP-Network Security, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------


  • 2.  RE: ClearPass 6.11 stopping services during update installation

    EMPLOYEE
    Posted Mar 16, 2023 06:59 AM

    Which update did you install and on what exact version of ClearPass (like 6.11.1->6.11.2)?

    Have you opened a TAC case for this? This does not sound right.

    Do you have a cluster and VIPs configured? Did the VIP perform a takeover by the other node (looks like as the VIP service is stopped)?



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: ClearPass 6.11 stopping services during update installation

    Posted Mar 16, 2023 08:02 AM

    Hi

    I have so far only tested in lab servers deployed from 6.11.1 ovf image installing 6.11.2.

    All the servers have been new installations, stand alone servers and no VIP configured.

    One after testing manual import of the update image and not generated any token, to verify the fix for offline updates in 6.11.1.

    Another after creating a token, download the image and install.

    Also seen the the behavior on a machine deployed with 6.11.0 and token generated, image 6.11.2 downloaded and installed.

    At the moment I don't have any more 6.11.0 servers where I can confirm this.

    So far I have not opened a TAC case on this, as I found it just before I posted the question in the forum. I was just interesed to know if it was something to expect. I can open at ticket and see what answer I get.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP 2023, ACCX #1335, ACMP, ACDP, ACP-Network Security, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: ClearPass 6.11 stopping services during update installation

    Posted Mar 17, 2023 04:36 AM

    A short update after opening a TAC case I got this answer:

    "I understand from the case description that you are facing issues with ClearPass-ClearPass 6.11 stopping services during update installation.
    Upon checking, it is a normal behavior and expected one in all updates/upgrades.
    The stopped services will be automatically running after reboot of the server on installation. So, it is not an issue. It's an expected behavior."

    If this is correct the documentation must be updated accordingly. Awaiting feedback from TAC.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP 2023, ACCX #1335, ACMP, ACDP, ACP-Network Security, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 5.  RE: ClearPass 6.11 stopping services during update installation

    EMPLOYEE
    Posted Mar 20, 2023 08:51 AM

    I just checked with an update 6.10.7->6.10.8 and see similar results between the patch install and the restart:

    Because the RADIUS and Policy service run, and the Virtual IP service does not, I may have never noticed before.

    Also, I tend to use the Cluster Update/Cluster Upgrade tool, which automatically triggers a reboot after the patch installation, in which case there is no time between the installation and the reboot.

    So, it seems that the most important services are restarted, but you will need to reboot in order to fully finish the reboot, which I think is mentioned as well.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 6.  RE: ClearPass 6.11 stopping services during update installation

    Posted Mar 20, 2023 12:24 PM

    That zone cache service is that a new name for multi-master cache ?

    I have done multiple upgrade from 6.5 - 6.6 and so on until 6.9 to 6.10 in the past, and even small patches update triggers services stop prior to reboot.




  • 7.  RE: ClearPass 6.11 stopping services during update installation

    EMPLOYEE
    Posted Mar 22, 2023 05:41 AM

    Yes, check here for all terminology changes in ClearPass 6.10.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------