This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problem restoring from a backup file

Hopefully someone can help me here, as I am going crazy...

I have spent in excess of 8 hours now trying to build a new UTM using a backup file to restore settings.
I have done this kind of recovery many times in the past, so the process is not new to me or something I would call difficult. That said, every time I import the backup file into a newly build UTM I cannot connect to the WebAdmin login page. I always receive a "This page can't be displayed" error.

Here is a simple breakdown of the build process I have been using:

  • Install a current version of the UTM from the installation ISO image (Home licence version).
  • When the UTM has installed, connect the UTM to a PC on the same subnet (connected directly via a crossover cable)
  • Open a browser window and go though the basic WebAdmin installation process. (https://192.168.xxx.x:4444)
  • Import the backup file
  • Reboot the UTM
  • Try to connect to the WebAdmin page
  • FAIL

After application of the backup file I can ping the UTM, but I cannot display the WebAdmin page in the browser.
I have also tried rebooting the UTM numerous times as well as manually restarting the httpd service at the console, neither of which made any difference.

I have used a manually created backup file from today (from current UTM) as well as numerous automatic backup files, going back 4 months (there have been no configuration changes in that time)
A few months ago I replaced my UTM with different hardware and did not have this problem. Why this is happening now is not logical, but it is.
I need to make some configuration changes soon, so I am upgrading to a slightly better box and adding another NIC (adding VOIP and an ATA on its own subnet).

Something else I have done is to restore a different UTM to the same hardware from a backup file. That works!
After that installation was up and running I applied my backup file and again it broke. So the process does work, just not with any of my backup files.

I have also tested with another box and the same thing happened, so it is not hardware related.

This is really bizarre and I have run out of ideas now as to why this is happening and how I can fix it.

Anyone have any ideas???



This thread was automatically locked due to age.
Parents
  • So... it turns out that the problem was not with the UTM version, it was an issue with IE11 on server 2012 R2.
    Probably should apologise for bagging out v9.404-5.1, but it certainly looked like this was the problem initially.

    Why IE allowed me to connect and go through the basic UTM configuration and then rejected the connection after applying the backup file still confuses me.
    The address to the login page did not change and I was able to restore a backup file from a different UTM, but I could not restore my own UTM's backup files. That's just bizarre.

    Should this happen to anyone else, use Chrome or Firefox to access the login page or try turning off "Use TLS 1.2" in the IE11 Internet Options/Advanced configuration settings. In the end, that worked for me.

    Bloody Microsoft.

  • sorry dont blame microsoft for this...

    its a sophos problem with using old crypto methods in their own ca.

    you have to update your internal ca to fix the problem. thats why you dont have connection problem with new installed 9.4x and have problems when using backup-file.

    fix your internal ca.. theres an kb article where it is described... cant find it now.. hope someone can post link to it..


    edit:

    found it: See https://community.sophos.com/kb/en-us/120851  at 4. Regenerate Certificates and regarding CAs


    editoff

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

Reply
  • sorry dont blame microsoft for this...

    its a sophos problem with using old crypto methods in their own ca.

    you have to update your internal ca to fix the problem. thats why you dont have connection problem with new installed 9.4x and have problems when using backup-file.

    fix your internal ca.. theres an kb article where it is described... cant find it now.. hope someone can post link to it..


    edit:

    found it: See https://community.sophos.com/kb/en-us/120851  at 4. Regenerate Certificates and regarding CAs


    editoff

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

Children
No Data