Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can't "cluster reset-database" on dropped Subscriber

This thread has been viewed 23 times
  • 1.  Can't "cluster reset-database" on dropped Subscriber

    Posted Nov 25, 2022 02:19 AM
    Hi everyone,

    After a suddently shutdown of the VM that was hosting my Subscriber ClearPass, once it was powered on again, the Subscriber appeared as "Out of Sync" and lately as "Node Disabled". 

    In order to fix it, i need to:
    1. Drop the failed Subscriber from the Publisher
    2. Reset db in Subscriber via CLI (cluster reset-database)
    3. Rejoin the Subscriber to the Publisher again

    In the Step 2 I faced an issue as it prompts the following error: 
    ERROR - Failed to reset database. Error: Command cd /tmp && sudo -H -u postgres pg_dump --schema=public -F c -t license_info tipsdb > /tmp/tmph4yLEb exited with error return or signal. Retcode=1. Status=256

    I thought it could be for the lack of space in the VM so I added the "-b" in the previous command in order to not to backup the db before reseting them, but the error remain the same.

    Any thoughts about it?

    Thanks!!
    A.


  • 2.  RE: Can't "cluster reset-database" on dropped Subscriber

    Posted Nov 25, 2022 03:15 AM
    Hi

    As you get an error message of this type when running the reset-database command after the power outage I would recommend a TAC case if you would like to troubleshoot.

    But as it's a VM a fresh install of a new VM server will solve the issue. In that case you need to have license, certificates and any settings changed on the server node under server manager, like SNMP settings, service specific settings, ACL's etc. Backups is also needed to restore the databases.
    The same information is also required if you continue with TAC and troubleshooting.

    ------------------------------
    Best Regards
    Jonas Hammarbäck
    ACCX #1335, ACMP, ACDP, ACNSP, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 3.  RE: Can't "cluster reset-database" on dropped Subscriber

    Posted Mar 04, 2024 09:25 PM

    you can use cluster reset-database -f to force it.  Please note, this will errase EVERYTHING including your license keys and passwords.  Like a brand new system but with IP addresses.  You will need to restore your certificates as well, including your CA Certs.




  • 4.  RE: Can't "cluster reset-database" on dropped Subscriber

    Posted Mar 05, 2024 05:23 AM

    I agree on that.