Upgrade
Upgrading Glasswall OVA
Please follow the steps below to upgrade your Glasswall OVA:
- Backup MongoDB data and create a mongodump.
kubectl port-forward svc/mongo-svc 27017
- Open another terminal on the VM:
username=$(kubectl get secret mongodb-cdrplatform-cdrp-user -o json | jq -r '.data.username' | base64 -d)
password=$(kubectl get secret mongodb-cdrplatform-cdrp-user -o json | jq -r '.data.password' | base64 -d)
mongodump -h localhost -p 27017 --db cdrplatform --out halo_backup -u "${username:?}" -p "${password:?}"
zip -r halo_backup.zip halo_backup
- Copy the backup zip file from the VM to a local machine.
scp glasswall@<ip-of-the-old-vm>:~/halo_backup.zip halo_backup.zip
-
Follow the steps in the deployment page based on VMWare or Hyper-V to create a new VM using the new OVA/VHD.
-
Copy the
halo_backup.zipfrom the local machine to the vVM.
scp halo_backup.zip glasswall@<ip-of-the-new-vm>:~/
- Restore the data in the new VM.
kubectl port-forward svc/mongo-svc 27017
- Open another terminal on the VM:
unzip halo_backup.zip
username=$(kubectl get secret mongodb-cdrplatform-cdrp-user -o json | jq -r '.data.username' | base64 -d)
password=$(kubectl get secret mongodb-cdrplatform-cdrp-user -o json | jq -r '.data.password' | base64 -d)
mongorestore --host localhost --port 27017 -u "${username:?}" -p "${password:?}" --authenticationMechanism=SCRAM-SHA-256 --authenticationDatabase=cdrplatform halo_backup
- Clean up the backup files after the restore:
rm -rf halo_backup halo_backup.zip
ReversingLabs after upgrade
After upgrading, ReversingLabs is disabled until you reconfigure it.
To restore it, follow Enable ReversingLabs: open the File reputation tab in the Portal (or use the Halo API), re-enter the endpoint and credentials, run Test connection, then turn it on and save.
ICAP after upgrade
The new appliance has the ICAP server installed but not running, so nothing answers on the ICAP ports until you turn it on.
To restore it, follow Enable ICAP: open the ICAP tab in the Portal, choose Enable ICAP server, and check your ICAP profiles once the server reports as running.