Steps to follow in order to add the IronPort device into the Cluster-(while using CCH key –port 2222)
a) Login to 192.168.1.2:
Before we could add the new device into the Cluster, we would need to remove the stale entry of older device from the cluster. In order to do so please follow the below steps
login to clusterconfiguration by running clusterconfig command
Hit the command “removemachine” and remove the machine from the cluster
Steps to add the new device :
(Machine ironport-c150-2.revenge.com) (SERVICE)> clusterconfig
This command is restricted to “cluster” mode. Would you like to switch to “cluster” mode? [Y]>Y
Cluster L-C150
Choose the operation you want to perform:
– ADDGROUP – Add a cluster group.
– SETGROUP – Set the group that machines are a member of.
– RENAMEGROUP – Rename a cluster group.
– DELETEGROUP – Remove a cluster group.
– REMOVEMACHINE – Remove a machine from the cluster.
– SETNAME – Set the cluster name.
– LIST – List the machines in the cluster.
– CONNSTATUS – Show the status of connections between machines in the cluster.
– COMMUNICATION – Configure how machines communicate within the cluster.
– DISCONNECT – Temporarily detach machines from the cluster.
– RECONNECT – Restore connections with machines that were previously detached.
– PREPJOIN – Prepare the addition of a new machine over CCS.
[]> list
Cluster L-C150
==============
Group Main_Group:
Machine ironport-c150-2.revenge.com (Serial #: 001D09FB7DE2-GJ5X4G1) -> Verified that only 192.168.1.2 was into the cluster
Cluster L-C150
Choose the operation you want to perform:
– ADDGROUP – Add a cluster group.
– SETGROUP – Set the group that machines are a member of.
– RENAMEGROUP – Rename a cluster group.
– DELETEGROUP – Remove a cluster group.
– REMOVEMACHINE – Remove a machine from the cluster.
– SETNAME – Set the cluster name.
– LIST – List the machines in the cluster.
– CONNSTATUS – Show the status of connections between machines in the cluster.
– COMMUNICATION – Configure how machines communicate within the cluster.
– DISCONNECT – Temporarily detach machines from the cluster.
– RECONNECT – Restore connections with machines that were previously detached.
– PREPJOIN – Prepare the addition of a new machine over CCS.
[]> prepjoin
Prepare Cluster Join Over CCS -> we would need to select the PrepJoin option in order to make the new IronPort device ready for CCS connection and to apply the key
No host entries waiting to be added to the cluster.
Choose the operation you want to perform:
– NEW – Add a new host that will join the cluster.
[]> new
Enter the hostname of the system you want to add.
[]> ironport-c150-1.revenge.com
Enter the serial number of the host ironport-c150-1.revenge.com.
[]> ******************
Enter the user key of the host ironport-c150-1.revenge.com.-> This can be obtained by typing “clusterconfig prepjoin print” in the CLI on ironport-c150-1.revenge.com.
=======================================================================
GO back to 192.168.1.1:
ironport-c150-1.revenge.com (SERVICE)> clusterconfig prepjoin print
Host: ironport-c150-1.revenge.com
Serial Number: ******************
User Key:
ssh-dss
AAAAB3NzaC1kc3MAAACBAJylPNMwuIwzGB9hZRMWbj8t9Caz6v/Dc7iCB2Md9nBq8g1xuXAf4pje
Ea+QMSleatRpPoVFhYP9iJEc+8fppxgiNAfvuJ9WjpUGDGWK0/1Zkp1h5wyrxZwSuhZoGo+v
Ea+QMSleatRpPoVFhYP9iJEc+4Hhp
VUz7fg2aJfo1YpW+wEmEM2d83YN8LAnsMtUnK2ZzAAAAFQDnoJ3LVN7KzD5+KGtwQd/aMZ6t
VUz7fg2aJfo1YpW+wEmEM2d83YN8LAnsMtUnK2ZzAAAAFQDnoJ3LVN7KzD5+SQAA
AIBz9Ax0KYfufEN0QhfFSawiOuCQqPqNEJTDHjPHZPzAl1x/G86v+oh85Vpp+rleaPU8fDEbf1RV
ixiYsKIu/Lj5qgoOb8FbiwB7siH3ioD2SG5YF/Rjw3NYtZSmT1HrmiW389cZTC//KgEL5o4JlyX1
8BqOApaO0gg8AdIvP7Z9OAAAAIBUyZ6uJDCPDhKxy2RuqKdYKfzgeARFPlGtbsnPk0V3Xgc4Eved
yWWhdLQ13/XXvZRS6aG2dyLBD0our8B+4CTwYgtaffzH5XKb6voigFJnuX3k2+bNONhIkSDeFw93
GTGUgUubDXdi/Azkx+mQaRu8RTssG2h1JBKxM0OW5Ps1Ow==
================================================================================
Continuing the addition process on 192.168.1.2 :
Copy the above content to the User Key section on Press enter on a blank line to finish.
ssh-dss
AAAAB3NzaC1kc3MAAACBAJylPNMwuIwzGB9hZRMWbj8t9Caz6v/Dc7iCB2Md9nBq8g1xuXAf4pje
Ea+QMSleatRpPoVFhYP9iJEc+8fppxgiNAfvuJ9WjpUGDGWK0/1Zkp1h5wyrxZwSuhZoGo+v
Ea+QMSleatRpPoVFhYP9iJEc+4Hhp
VUz7fg2aJfo1YpW+wEmEM2d83YN8LAnsMtUnK2ZzAAAAFQDnoJ3LVN7KzD5+KGtwQd/aMZ6t
VUz7fg2aJfo1YpW+wEmEM2d83YN8LAnsMtUnK2ZzAAAAFQDnoJ3LVN7KzD5+SQAA
AIBz9Ax0KYfufEN0QhfFSawiOuCQqPqNEJTDHjPHZPzAl1x/G86v+oh85Vpp+rleaPU8fDEbf1RV
ixiYsKIu/Lj5qgoOb8FbiwB7siH3ioD2SG5YF/Rjw3NYtZSmT1HrmiW389cZTC//KgEL5o4JlyX1
8BqOApaO0gg8AdIvP7Z9OAAAAIBUyZ6uJDCPDhKxy2RuqKdYKfzgeARFPlGtbsnPk0V3Xgc4Eved
yWWhdLQ13/XXvZRS6aG2dyLBD0our8B+4CTwYgtaffzH5XKb6voigFJnuX3k2+bNONhIkSDeFw93
GTGUgUubDXdi/Azkx+mQaRu8RTssG2h1JBKxM0OW5Ps1Ow==
Host ironport-c150-1.revenge.com added.
============================================================================
=
Once the device is configured to use CCH key, login to 192.168.1.1 once again and run the below commands to add the device into the cluster
ironport-c150-1.revenge.com (SERVICE)> clusterconfig
Do you want to join or create a cluster?
1. No, configure as standalone.
2. Create a new cluster.
3. Join an existing cluster over SSH.
4. Join an existing cluster over CCS.
[1]> 4
While joining a cluster, you will need to validate the SSH host key of the remote machine to which you are joining. To get the public host key fingerprint of the remote host, connect to the cluster and run: logconfig -> hostkeyconfig -> fingerprint.
In order to join a cluster over CCS, you must first log in to the cluster and tell it that this system is being added. On a machine in the cluster, run “clusterconfig -> prepjoin -> new” with the following information and commit.
Host: ironport-c150-1.revenge.com
Serial Number: *****************
User Key:
ssh-dss
AAAAB3NzaC1kc3MAAACBAJylPNMwuIwzGB9hZRMWbj8t9Caz6v/Dc7iCB2Md9nBq8g1xuXAf4pje
Ea+QMSleatRpPoVFhYP9iJEc+8fppxgiNAfvuJ9WjpUGDGWK0/1Zkp1h5wyrxZwSuhZoGo+v
Ea+QMSleatRpPoVFhYP9iJEc+4Hhp
VUz7fg2aJfo1YpW+wEmEM2d83YN8LAnsMtUnK2ZzAAAAFQDnoJ3LVN7KzD5+KGtwQd/aMZ6t
VUz7fg2aJfo1YpW+wEmEM2d83YN8LAnsMtUnK2ZzAAAAFQDnoJ3LVN7KzD5+SQAA
AIBz9Ax0KYfufEN0QhfFSawiOuCQqPqNEJTDHjPHZPzAl1x/G86v+oh85Vpp+rleaPU8fDEbf1RV
ixiYsKIu/Lj5qgoOb8FbiwB7siH3ioD2SG5YF/Rjw3NYtZSmT1HrmiW389cZTC//KgEL5o4JlyX1
8BqOApaO0gg8AdIvP7Z9OAAAAIBUyZ6uJDCPDhKxy2RuqKdYKfzgeARFPlGtbsnPk0V3Xgc4Eved
yWWhdLQ13/XXvZRS6aG2dyLBD0our8B+4CTwYgtaffzH5XKb6voigFJnuX3k2+bNONhIkSDeFw93
GTGUgUubDXdi/Azkx+mQaRu8RTssG2h1JBKxM0OW5Ps1Ow==
Choose the interface on which to enable the Cluster Communication Service:
1. Management (192.168.1.1/26: ironport1.revenge.com) [1]> 1
Enter the port on which to enable the Cluster Communication Service:
[2222]>
Enter the IP address of a machine in the cluster.
[]> 192.168.1.2
Enter the remote port to connect to. This must be the CCS port on the machine “192.168.1.2”, not the normal admin ssh port.
[2222]>
Joining cluster group Main_Group.
Joining a cluster takes effect immediately; there is no need to commit.
Now the devices are into the cluster and below commands were used to see what are the devices which are running into the cluster:
To check on both system run clusterconfig , list
Cluster L-C150) (SERVICE)> clusterconfig
Cluster L-C150
Choose the operation you want to perform:
– ADDGROUP – Add a cluster group.
– SETGROUP – Set the group that machines are a member of.
– RENAMEGROUP – Rename a cluster group.
– DELETEGROUP – Remove a cluster group.
– REMOVEMACHINE – Remove a machine from the cluster.
– SETNAME – Set the cluster name.
– LIST – List the machines in the cluster.
– CONNSTATUS – Show the status of connections between machines in the cluster.
– COMMUNICATION – Configure how machines communicate within the cluster.
– DISCONNECT – Temporarily detach machines from the cluster.
– RECONNECT – Restore connections with machines that were previously detached.
– PREPJOIN – Prepare the addition of a new machine over CCS.
[]> list
Cluster L-C150
==============
Group Main_Group:
Machine ironport-c150-1.revenge.com
Machine ironport-c150-2.revenge.com
Note : please note that cluster group name is Cluster L-C150