Cisco IPS-4255-K9 Installation Guide - Page 333

Issues With Automatic Update, Updating a Sensor with the Update Stored on the Sensor

Page 333 highlights

Chapter A Troubleshooting Troubleshooting the Appliance Issues With Automatic Update The following list provides suggestions for troubleshooting automatic updates: • Run TCPDUMP - Create a service account. Su to root and run TCPDUMP on the command and control interface to capture packets between the sensor and the FTP server. - Use the upgrade command to manually upgrade the sensor. - Look at the TCPDUMP output for errors coming back from the FTP server. • Make sure the sensor is in the correct directory. The directory must be specified correctly. This has caused issues with Windows FTP servers. Sometimes an extra "/" or even two "/" are needed in front of the directory name. To verify this, use the same FTP commands you see in the TCPDUMP output through your own FTP connection. • You must use the Windows FTP server setup option to emulate UNIX file structure and not MS-DOS file structure. • If you are using SCP, make sure you have added the SSH host key to the known hosts list. Try the manual upgrade command before attempting the automatic update. If it works with the upgrade command and does not work with the automatic update, try the following: • Determine which IPS software version your sensor has. • Make sure the passwords are configured for automatic update. Make sure they match the same passwords used for manual update. • Make sure that the filenames in the FTP server are exactly what you see on Downloads on Cisco.com. This includes capitalization. Some Windows FTP servers allow access to the file with the incorrect capitalization but the sensor ultimately rejects the file because the name has changed. • If necessary, run TCPDUMP on automatic update. You can compare the successful manual update with the unsuccessful automatic update and troubleshoot from there. For More Information • For the procedure for creating the service account, see Creating the Service Account, page A-5. • For the procedure for reimaging your sensor, see Chapter 12, "Upgrading, Downgrading, and Installing System Images." • For the procedure for adding hosts to the SSH known hosts list, refer to Adding Hosts to the SSH Known Hosts List. • For the procedure for determining the software version, see Displaying Version Information, page A-74. Updating a Sensor with the Update Stored on the Sensor You can store the update package in the /var directory on the sensor and update the sensor from there if you need to. To update the sensor with an update stored on the sensor, follow these steps: Step 1 Step 2 Log in to the service account. Obtain the update package file from Cisco.com. OL-18504-01 Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0 A-55

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412

A-55
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
OL-18504-01
Chapter A
Troubleshooting
Troubleshooting the Appliance
Issues With Automatic Update
The following list provides suggestions for troubleshooting automatic updates:
Run TCPDUMP
Create a service account.
Su
to root and run TCPDUMP on the command and control interface
to capture packets between the sensor and the FTP server.
Use the
upgrade
command to manually upgrade the sensor.
Look at the TCPDUMP output for errors coming back from the FTP server.
Make sure the sensor is in the correct directory.
The directory must be specified correctly. This has caused issues with Windows FTP servers.
Sometimes an extra “/” or even two “/” are needed in front of the directory name.
To verify this, use the same FTP commands you see in the TCPDUMP output through your own FTP
connection.
You must use the Windows FTP server setup option to emulate UNIX file structure and not MS-DOS
file structure.
If you are using SCP, make sure you have added the SSH host key to the known hosts list.
Try the manual
upgrade
command before attempting the automatic update. If it works with the
upgrade
command and does not work with the automatic update, try the following:
Determine which IPS software version your sensor has.
Make sure the passwords are configured for automatic update. Make sure they match the same
passwords used for manual update.
Make sure that the filenames in the FTP server are exactly what you see on Downloads on
Cisco.com. This includes capitalization.
Some Windows FTP servers allow access to the file with the incorrect capitalization but the sensor
ultimately rejects the file because the name has changed.
If necessary, run TCPDUMP on automatic update. You can compare the successful manual update
with the unsuccessful automatic update and troubleshoot from there.
For More Information
For the procedure for creating the service account, see
Creating the Service Account, page A-5
.
For the procedure for reimaging your sensor, see
Chapter 12, “Upgrading, Downgrading, and
Installing System Images.”
For the procedure for adding hosts to the SSH known hosts list, refer to
Adding Hosts to the SSH
Known Hosts List
.
For the procedure for determining the software version, see
Displaying Version Information,
page A-74
.
Updating a Sensor with the Update Stored on the Sensor
You can store the update package in the /var directory on the sensor and update the sensor from there if
you need to. To update the sensor with an update stored on the sensor, follow these steps:
Step 1
Log in to the service account.
Step 2
Obtain the update package file from Cisco.com.