Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Only Administrator can access the auxiliary device

Since upgrading to 16.05.2 on my HA A/P cluster I been having some weird things happen.

Firstly, when I did the update to 16.05.2 one of the units in the HA dropped off. This was a new setup not yet in production so I was happy to take the latest version for a spin. I continued configuring the cluster as I couldn't get onsite to see what was happening, but when I finally did get back onsite and reboot the broken one, it continued the update, became the master, and wiped all the configuration I made since. I understand why this happened, but it was a real pain.

Then, after setting up an IPSEC VPN the device has become really slow. Any attempt to make a configuration change (eg adding an IPSEC route from the command line) takes minutes to complete.

And tonight when I try and log in I get "Only Administrator can access the auxiliary device". I'm logging in as admin, and i'm logging in to the WAN address on an A/P cluster so I can only be logging in to the primary device. When I try to log in by SSH I just get access denied.

Can anyone suggest any tricks I could use to get access, or am I going to have to go onsite to resolve this? I was already there today and going back is going to be a significant inconvenience.

Also, is there any way I could roll back to 16.05.01 and still retain my configuration? I've invested a fair bit of time getting it to this point. I believe a backup shouldn't be restored to an earlier firmware, but what about some combination of exports and imports?

Thanks

James



This thread was automatically locked due to age.
  • It turns out that the reason for the problem is that the networks at each end of the VPN overlap, and once I changed the route priority the HA got itself very confused.

    For some reason this confusion resulted in the admin password getting corrupted, but once I fixed that and turned off the VPN, everything appears to be back in good order.

    Some network renumbering will be required :(