fir3net
PPS-Firenetbanner-780.5x190-30-03-17

Backup / Restore a Juniper NSM

This article will show you how to backup and restore your Juniper NSM. This article was written using NSM version 2008.2r1.
Within NSM the HighAvailSvr contains processes that run in both HA and non-HA mode and handles database backups and a watchdog daemon to restart NSM processes in case of failure.

Backup

Even though you will have your NSM configured to run automated backups. You may need to run a manual backup before making any major changes (such as upgrades etc).

To create a manual backup run the following,

[root@localhost /]# sudo -u nsm /usr/netscreen/HaSvr/utils/replicateDb backup

This should run through and create a manual backup. If not you may get the following error,

[root@localhost utils]# sudo -u nsm /usr/netscreen/HaSvr/utils/replicateDb backup
 Got arguments: backup.  This might take a while to process ...
Ha/Backup: FAIL

This will most likey be down to permission issues. The following should help you resolve the issue,

  • Error Log - /usr/netscreen/HaSvr/bin/.backupDoLocal.result
  • Locate the problem files - find /usr/netscreen /var/netscreen ! -group nsm ! -user nsm
  • Run the setperm/rync scripts. Steps can be found in the Juniper Knowledge base KB12188

Its worth noting that you may find no files using the find command which are not owned by nsm and also you may receive little or no errors in the logs to help you troubleshoot the issue.

In this instance you will need to stop all servers and run the set permissions scripts, this will require you running the following commands,

[root@localhost ~]# cd /usr/netscreen/HaSvr/utils
[root@localhost ~]# ./restoreDbFromBackup.sh /var/netscreen/dbbackup/[backup]

Useful Files

/usr/netscreen/HaSvr/bin/.haDoLocal.result  Logfile - Contains the syntax used to perform the local daily backup.
/usr/netscreen/HaSvr/bin/.backupDoLocal.result Logfile - Contains Rsync errors. 
/usr/netscreen/HaSvr/var/errorLog/backup.log Logfile - Contains the replicateDb script log.  
/usr/netscreen/HaSvr/utils/setRsyncUser Script - Set rsync user script 
/usr/netscreen/GuiSvr/utils/setperms.sh Script - Set permissions script 
/var/netscreen/dbbackup/exclude.rsync Configuration file - Exclude folders from local backup. 
/usr/netscreen/HaSvr/var/haSvr.cfg Configuration file - Backup configuration file.
/var/netscreen/dbbackup/ Directory - Default backup directory.  

  

Tags: Juniper, NSM

About the Author

RDonato

R Donato

Rick Donato is the Founder and Chief Editor of Fir3net.com. He currently works as a Principal Network Security Engineer and has a keen interest in automation and the cloud.

You can find Rick on Twitter @f3lix001