This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

HA is stuck in up2date

We have 2 x SG330 and we startet the update installation in GUI as usual. The master went through but the slave is no stuck at "up2date" for 12 hours.

Log below.

a)

Should we simply reboot the slave?

b)

Or disconnect the slave from the HA, reset it and reconnect it so it can resync?

c)

Or rebuild the HA by simply turning it off?

Turn HA off....it will alert you that slave will go off (shutdown) and it will perform factory reset on slave. everything should be done without your additional actions
Turn back on HA on "master" (choose Automatically). Start slave and HA will sync from scratch.

 

2016:11:11-08:45:16 sg330a-2 audld[13011]: Could not connect to Authentication Server us1.utmu2d.sophos.com (code=500 500 Internal Server Error).

2016:11:11-08:45:23 sg330a-2 audld[13011]: id="3701" severity="info" sys="system" sub="up2date" name="Authentication successful"

2016:11:11-08:45:23 sg330a-2 audld[13011]: Using static download server list in HA mode

2016:11:11-09:00:02 sg330a-2 audld[16239]: running on HA master system or cluster node

2016:11:11-09:00:02 sg330a-2 audld[16239]: Starting Up2Date Package Downloader

2016:11:11-09:00:02 sg330a-2 audld[16239]: patch up2date possible

2016:11:11-09:00:02 sg330a-2 audld[16239]: Using static update server list in HA mode

2016:11:11-09:00:37 sg330a-2 audld[16239]: id="3701" severity="info" sys="system" sub="up2date" name="Authentication successful"

2016:11:11-09:00:37 sg330a-2 audld[16239]: Using static download server list in HA mode

2016:11:11-09:00:37 sg330a-2 audld[16239]: id="3707" severity="info" sys="system" sub="up2date" name="Successfully synchronized fileset" status="success" action="download" package="avira-xvdf"

2016:11:11-09:00:38 sg330a-2 audld[16239]: id="3707" severity="info" sys="system" sub="up2date" name="Successfully synchronized fileset" status="success" action="download" package="aptp"

2016:11:11-09:00:38 sg330a-2 auisys[16485]: running on HA master system or cluster node

2016:11:11-09:00:38 sg330a-2 auisys[16485]: waiting for db_verify to return (30 seconds max)

2016:11:11-09:00:39 sg330a-2 auisys[16485]: not cleaning /var/up2date/sys-install in --nosys mode

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/appctrl43-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/aptp-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/avira-xvdf-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/cadata-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/clvbrowser-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/geoip-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/ipsbundle-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/man9-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/ohelp9-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: removing '/var/up2date/savi-install'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: Starting Up2Date Package Installer

2016:11:11-09:00:39 sg330a-2 auisys[16485]: No suitable packages of type <man9> found, skipping

2016:11:11-09:00:39 sg330a-2 auisys[16485]: No suitable packages of type <clvbrowser> found, skipping

2016:11:11-09:00:39 sg330a-2 auisys[16485]: No suitable packages of type <appctrl43> found, skipping

2016:11:11-09:00:39 sg330a-2 auisys[16485]: No suitable packages of type <ohelp9> found, skipping

2016:11:11-09:00:39 sg330a-2 auisys[16485]: No suitable packages of type <cadata> found, skipping

2016:11:11-09:00:39 sg330a-2 auisys[16485]: No suitable packages of type <geoip> found, skipping

2016:11:11-09:00:39 sg330a-2 auisys[16485]: No suitable packages of type <ipsbundle> found, skipping

2016:11:11-09:00:39 sg330a-2 auisys[16485]: No suitable packages of type <savi> found, skipping

2016:11:11-09:00:39 sg330a-2 auisys[16485]: Install u2d packages <aptp>

2016:11:11-09:00:39 sg330a-2 auisys[16485]: Starting installing up2date packages for type 'aptp'

2016:11:11-09:00:39 sg330a-2 auisys[16485]: Installing up2date package: /var/up2date/aptp/u2d-aptp-9.19225.tgz.gpg

2016:11:11-09:00:39 sg330a-2 auisys[16485]: Verifying up2date package signature

2016:11:11-09:00:39 sg330a-2 auisys[16485]: Unpacking installation instructions

2016:11:11-09:00:39 sg330a-2 auisys[16485]: parsing installation instructions

2016:11:11-09:00:39 sg330a-2 auisys[16485]: Unpacking up2date package container

2016:11:11-09:00:39 sg330a-2 auisys[16485]: Running pre-installation checks

2016:11:11-09:00:40 sg330a-2 auisys[16485]: Starting up2date package installation

2016:11:11-09:00:51 sg330a-2 auisys[16485]: id="371Z" severity="info" sys="system" sub="up2date" name="Successfully installed Up2Date package" status="success" action="install" package_version="9.19225" package="aptp"

2016:11:11-09:00:51 sg330a-2 auisys[16485]: [INFO-306] New Pattern Up2Dates installed

2016:11:11-09:00:51 sg330a-2 auisys[16485]: Install u2d packages <avira-xvdf>

2016:11:11-09:00:51 sg330a-2 auisys[16485]: Starting installing up2date packages for type 'avira-xvdf'

2016:11:11-09:00:51 sg330a-2 auisys[16485]: Installing up2date package: /var/up2date/avira-xvdf/u2d-avira-xvdf-9.4021-4022.patch.tgz.gpg

2016:11:11-09:00:51 sg330a-2 auisys[16485]: Verifying up2date package signature

2016:11:11-09:00:51 sg330a-2 auisys[16485]: Unpacking installation instructions

2016:11:11-09:00:51 sg330a-2 auisys[16485]: parsing installation instructions

2016:11:11-09:00:51 sg330a-2 auisys[16485]: This is a patch. Setting required_version to 9.4021

2016:11:11-09:00:51 sg330a-2 auisys[16485]: Unpacking up2date package container

2016:11:11-09:00:51 sg330a-2 auisys[16485]: Running pre-installation checks

2016:11:11-09:00:52 sg330a-2 auisys[16485]: Starting up2date package installation

2016:11:11-09:01:04 sg330a-2 auisys[16485]: id="371Z" severity="info" sys="system" sub="up2date" name="Successfully installed Up2Date package" status="success" action="install" package_version="9.4022" package="avira-xvdf"

2016:11:11-09:01:04 sg330a-2 auisys[16485]: [INFO-306] New Pattern Up2Dates installed

2016:11:11-09:01:05 sg330a-2 auisys[16485]: Up2Date Package Installer finished, exiting

2016:11:11-09:01:05 sg330a-2 auisys[16485]: id="3716" severity="info" sys="system" sub="up2date" name="Up2Date Package Installer finished, exiting"

2016:11:11-09:15:01 sg330a-2 audld[19437]: running on HA master system or cluster node

2016:11:11-09:15:01 sg330a-2 audld[19437]: Starting Up2Date Package Downloader

2016:11:11-09:15:02 sg330a-2 audld[19437]: patch up2date possible

2016:11:11-09:15:02 sg330a-2 audld[19437]: Using static update server list in HA mode



This thread was automatically locked due to age.
  • Hi,

    I would suggest option B. There can be a backend glitch which may force up2date to cause error.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • 1)

    How can I easily reset my slave? Shutdown via WebGUI, disconnect eth03 (sync)l, connect a notebook, login and factory reset, reconnect eth03 and boot the slave?

     

    2)

    I also see that I can shell (putty) into the master and " ha_utils ssh " to connect to the slave node and the reset the slave node directly to factory?

    1. Login to the UTM console or SSH as loginuser.
    2. Switch to Slave by using ha_utils ssh
    3. Enter su to login as root.
    4. Enter: cc
    5. Enter: RAW
    6. Enter: system_factory_reset

     

    3)

    This knowledge base entry (from 2014) even suggest to downgrade the master to the slave version https://community.sophos.com/kb/zh-cn/120870

    • Logon to the WebAdmin on the Master 
    • Navigate to Management | Up2Date
    • click on 'Install' for the version which is currently installed on the slave -> this will force a reboot with NO takeover.

     

    4)

    I also see that I can shell (putty) into the master and " ha_utils ssh " and delete the updates file and manually initiate the update https://community.sophos.com/kb/en-us/121765

    Using the following commands remove the redundant packages from these locations (of the non responsive slave):

    • # rm -rf /var/up2date/sys-install/*
    • # rm /var/up2date/sys/*
    • # rm /var/up2date/.queue/*

    Then either manually wget the updates and manually start the up2date using auisys.plx or wait for the master to force the slave to redownload and reinstall (if ever).

     

     

    hu_utils says:

    SLAVE: 1 Node1 198.19.250.1 9.407003 UP2DATE since Thu Nov 10 18:58:49 2016
    MASTER: 2 Node2 198.19.250.2 9.408004 ACTIVE since Thu Nov 10 18:58:49 2016

  • often a simple reboot solves the up2date problems.

    would use Webadmins HA console or Frontpannel keys.

    If this don't help...

    delete up2date files as explained within your variant 4) and reboot system afterwards.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Rebooting didn't change anything.

    Deleting the updates files from the non-responding node directly using ha_utils ssh and the commands below helped.

    -> Using the following commands remove the redundant packages from these locations (of the non responsive slave):

    • # rm -rf /var/up2date/sys-install/*
    • # rm /var/up2date/sys/*
    • # rm /var/up2date/.queue/* 
  • A tip for future updates.
    My HA up2date often failed until I started using this procedure, supplied by "Manfred" some years ago:

    1. Reboot HA slave - wait for the 'fully functional' mail
    2. Reboot HA master - wait for the fully functional' mail
    3. Install up2date

    I haven't installed UTM 9.408-4 on my 2 SG30, so I don't know is there are any general problems with the release.