简介
本文档介绍如何对身份服务引擎(ISE)进行按需配置数据和操作数据备份。
先决条件
要求
Cisco 建议您了解以下主题:
- 身份服务引擎(ISE)的基础知识。
- 如何配置存储库。
使用的组件
本文档中的信息基于以下软件和硬件版本:
本文档中的信息都是基于特定实验室环境中的设备编写的。本文档中使用的所有设备最初均采用原始(默认)配置。如果您的网络处于活动状态,请确保您了解所有命令的潜在影响。
背景信息
另一个确保ISE在环境中的可用性的关键策略是拥有可靠的备份策略。有两种类型的ISE备份:配置备份和操作备份。
思科ISE允许您备份来自主PAN和监控节点的数据。备份可以从CLI或用户界面完成。
配置数据-包含特定应用和Cisco ADE操作系统配置数据。可以使用GUI或CLI通过主PAN进行备份。
运行数据-包含监控和故障排除数据。可以通过主PAN GUI或使用监控节点的CLI进行备份。
备份存储在存储库中,并且可以从同一存储库中恢复。您可以安排自动运行备份,也可以按需手动运行备份。您可以从GUI或CLI查看备份的状态,但只能从CLI查看还原的状态。
注意:思科ISE不支持用于备份ISE数据的VMware快照。使用VMware快照或任何第三方备份来备份ISE数据会导致停止思科ISE服务。
配置
从GUI执行按需ISE配置数据备份
步骤1:配置存储库请参阅如何在ISE上配置存储库
第二步: 登录ISE,导航到管理>系统>备份和恢复,选择配置数据备份,点击立即备份,如图所示:
第三步:提供备份名称、存储库名称和加密密钥,然后单击备份。
提示:请确保您记得加密密钥。
注意:ISE配置备份包含系统和受信任证书,并且不包含内部证书颁发机构(CA)证书。
从ISE CLI手动备份内部证书颁发机构(CA)存储。通过SSH登录到ISE主管理节点(PAN)节点,然后运行命令application configure ise > select option 7以导出内部CA存储。
ise/admin# application configure ise
Selection configuration option
[1]Reset M&T Session Database
[2]Rebuild M&T Unusable Indexes
[3]Purge M&T Operational Data
[4]Reset M&T Database
[5]Refresh Database Statistics
[6]Display Profiler Statistics
[7]Export Internal CA Store
[8]Import Internal CA Store
[9]Create Missing Config Indexes
[10]Create Missing M&T Indexes
[11]Enable/Disable ACS Migration
[12]Generate Daily KPM Stats
[13]Generate KPM Stats for last 8 Weeks
[14]Enable/Disable Counter Attribute Collection
[15]View Admin Users
[16]Get all Endpoints
[17]Enable/Disable Wifi Setup
[18]Reset Config Wifi Setup
[19]Establish Trust with controller
[20]Reset Context Visibility
[21]Synchronize Context Visibility With Database
[22]Generate Heap Dump
[23]Generate Thread Dump
[24]Force Backup Cancellation
[25]CleanUp ESR 5921 IOS Crash Info Files
[0]Exit
7
Export Repository Name: FTP-Repo
Enter encryption-key for export:
Security Protocol list Start
Inside Session facade init
Old Memory Size : 7906192
Old Memory Size : 7906192
Export in progress...
Old Memory Size : 7906192
The next 5 CA key pairs were exported to repository 'FTP-Repo' at 'ise_ca_key_pairs_of_ise':
Subject:CN=Certificate Services Root CA - ise
Issuer:CN=Certificate Services Root CA - ise
Serial#:0x08f06033-2a4c4fcc-b297e75a-04f11bf9
Subject:CN=Certificate Services Node CA - ise
Issuer:CN=Certificate Services Root CA - ise
Serial#:0x3a0e8d8a-5a2846be-a902c280-b5d678aa
Subject:CN=Certificate Services Endpoint Sub CA - ise
Issuer:CN=Certificate Services Node CA - ise
Serial#:0x33b14150-596c4552-ad0a9ab1-9541f0bb
Subject:CN=Certificate Services Endpoint RA - ise
Issuer:CN=Certificate Services Endpoint Sub CA - ise
Serial#:0x37e17494-cf1d4372-bf0ba1e6-83653826
Subject:CN=Certificate Services OCSP Responder - ise
Issuer:CN=Certificate Services Node CA - ise
Serial#:0x68a694ed-bc48481d-bc6cc58e-60a44a61
ise CA keys export completed successfully
从CLI执行按需ISE配置数据备份
backup <backup file name> repository <repository name> ise-config encryption-key plain <encryption key>
ise/admin# backup ConfigBackup-CLI repository FTP-Repo ise-config encryption-key plain <backup password>
% Internal CA Store is not included in this backup. It is recommended to export it using "application configure ise" CLI command
% Creating backup with timestamped filename: ConfigBackup-CLI-CFG10-200326-0705.tar.gpg
% backup in progress: Starting Backup...10% completed
% backup in progress: Validating ISE Node Role...15% completed
% backup in progress: Backing up ISE Configuration Data...20% completed
% backup in progress: Backing up ISE Indexing Engine Data...45% completed
% backup in progress: Backing up ISE Logs...50% completed
% backup in progress: Completing ISE Backup Staging...55% completed
% backup in progress: Backing up ADEOS configuration...55% completed
% backup in progress: Moving Backup file to the repository...75% completed
% backup in progress: Completing Backup...100% completed
ise/admin#
从GUI执行按需ISE操作数据备份
登录ISE GUI,导航到管理>系统>备份和恢复,选择操作数据备份,点击立即备份,如图所示:
第三步:提供备份名称、存储库名称和加密密钥,然后单击备份。
从CLI执行按需ISE操作数据备份
backup <backup file name> repository <repository name> ise-operational encryption-key plain <encryption key>
ise/admin# backup Ops-Backup-CLI repository FTP-Repo ise-operational encryption-key plain <backup password>
% Creating backup with timestamped filename: Ops-Backup-CLI-OPS10-200326-0719.tar.gpg
% backup in progress: Starting Backup...10% completed
% backup in progress: starting dbbackup using expdp.......20% completed
% backup in progress: starting cars logic.......50% completed
% backup in progress: Moving Backup file to the repository...75% completed
% backup in progress: Completing Backup...100% completed
ise/admin#
验证
导航到管理>系统>备份和恢复,查看配置数据备份进度,如图所示:
导航到管理>系统>备份和恢复以查看操作数据备份进度,如图所示:
ise/admin# show backup status
%% Configuration backup status
%% ----------------------------
% backup name: ConfigBackup-CLI
% repository: FTP-Repo
% start date: Thu Mar 26 07:05:11 IST 2020
% scheduled: no
% triggered from: CLI
% host:
% status: Backup is in progress
% progress %: 50
% progress message: Backing up ISE Logs
%% Operation backup status
%% ------------------------
% No data found. Try 'show backup history' or ISE operation audit report
ise/admin#
备份完成后,您可以看到Backup Status为success。
故障排除
确保ISE索引引擎服务正在ISE管理节点上运行。
ise-1/admin# show application status ise
ISE PROCESS NAME STATE PROCESS ID
--------------------------------------------------------------------
Database Listener running 15706
Database Server running 89 PROCESSES
Application Server running 25683
Profiler Database running 23511
ISE Indexing Engine running 28268
AD Connector running 32319
M&T Session Database running 23320
M&T Log Processor running 16272
要在ISE上调试备份恢复,请使用以下调试:
ise-1/admin# debug backup-restore backup ?
<0-7> Set level, from 0 (severe only) to 7 (all)
<cr> Carriage return.
ise-1/pan# debug backup-restore backup 7
ise-1/pan#
ise-1/pan# 6 [25683]:[info] backup-restore:backup: br_history.c[549] [system]: ISE backup/restore initiated by web UI as ise.br.status is 'in-progress' in /tmp/ise-cfg-br-flags
7 [25683]:[debug] backup-restore:backup: br_backup.c[600] [system]: initiating backup Config-Backup to repos FTP-Repo
7 [25683]:[debug] backup-restore:backup: br_backup.c[644] [system]: no staging url defined, using local space
7 [25683]:[debug] backup-restore:backup: br_backup.c[60] [system]: flushing the staging area
7 [25683]:[debug] backup-restore:backup: br_backup.c[673] [system]: creating /opt/backup/backup-Config-Backup-1587431770
7 [25683]:[debug] backup-restore:backup: br_backup.c[677] [system]: creating /opt/backup/backup-Config-Backup-1587431770/backup/cars
7 [25683]:[debug] backup-restore:backup: br_backup.c[740] [system]: creating /opt/backup/backup-Config-Backup-1587431770/backup/ise
7 [25683]:[debug] backup-restore:backup: br_backup.c[781] [system]: calling script /opt/CSCOcpm/bin/isecfgbackup.sh
6 [25683]:[info] backup-restore:backup: br_backup.c[818] [system]: adding ADEOS files to backup
6 [25683]:[info] backup-restore:backup: br_backup.c[831] [system]: Backup password provided by user
6 [25683]:[info] backup-restore:backup: br_backup.c[190] [system]: No post-backup entry in the manifest file for ise
7 [25683]:[debug] backup-restore:backup: br_backup.c[60] [system]: flushing the staging area
6 [25683]:[info] backup-restore:backup: br_backup.c[912] [system]: backup Config-Backup-CFG10-200421-0646.tar.gpg to repository FTP-Repo: success
6 [25683]:[info] backup-restore:backup: br_history.c[487] [system]: updating /tmp/ise-cfg-br-flags with status: complete and message: backup Config-Backup-CFG10-200421-0646.tar.gpg to repository FTP-Repo: success
请使用no debug backup-restore backup 7禁用节点上的调试。
ise-1/admin# no debug backup-restore backup 7