Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Does the CPPM 6.5 upgrade tool disrupt a clustered service during upgrade

This thread has been viewed 0 times
  • 1.  Does the CPPM 6.5 upgrade tool disrupt a clustered service during upgrade

    Posted May 12, 2015 05:53 AM

    Hi,

    Although I've been running 6.5.1 on my CPPM dev server for quite some time, my production service is still running 6.4.5. I've downloaded CPPM 6.5 onto all the cluster servers and the 6.5 installation tool onto the master publisher.

     

    Authentication requests are load balanced across all cluster servers via a front end F5 box based upon client calling station id. Health checks are in place to ensure an auth request doesn't hit an unavailable cluster server.

     

    Will there be any service disruption when performing the upgrade?

     

    Do I have to do anything configuration wise before I run the tool? I seem to remember that I had to tweak the length of time before the secondary publisher kicks in to take over from the master in previous upgrades.

     

    Any other gotcha's with running the upgrade utility?

     

    Rgds

    Alex

     



  • 2.  RE: Does the CPPM 6.5 upgrade tool disrupt a clustered service during upgrade

    EMPLOYEE
    Posted May 13, 2015 08:12 AM

    There shouldn't be any disruption assuming that your F5 and failover mechanisms are in place.  However, I would open up a support case if case of any issues



  • 3.  RE: Does the CPPM 6.5 upgrade tool disrupt a clustered service during upgrade

    Posted May 14, 2015 10:50 PM

    have not gone to 6.5 yet but when we went to 6.4 and used the tool.  The Upgrade process went fine while the Publisher was being upgraded. once completed and rebooted we lost all of our role caching (main concern was the role for [Machine Authentication]  was cleared.   All of our roles that used the Machine Authentication Failed until the user took action. (we machine/user authenticate).   While we don't have a load balancer and were not concerenced about uninteruppted service for captive portal.   Next time I upgrade I'll be making sure that I have a safe-guard in-place so our users don't notice.   Hope this helps.   

     

    Also if you have upgraded to 6.5 and used the tool I would be curious to know if you had same issue.