Hi.
We have a customer running about 60 SMB appliances, all of them using R77.20.x (1430) or R81.10.x (1530).
(Yes, the customer knows that the 1430s have to be replaced in the next months. 😉)
My problem is with the 1530s. At the moment I have 4 of them where I cannot install policy. If I do a "fw fetch" on them I get this:
[Expert@cp-xxx01]# fw fetch
ndb_open : failed for /opt/fw1/database/fwauth.NDB: Read-only file system
fwa_db_init: fwdab_init failed
fwd_reload_database: Error loading from fwauth.NDB
Fetching Security Policy from 'aaa.bbb.ccc.ddd'
Local Security Policy is Up-To-Date.
Error: Failed to run policy installation wrapper.
sfw_fetch_callback: Failed to execute command '"/opt/fw1/bin/fw" fetchlocal -d "/opt/fw1/state/local/FW1"'. rc=1, exit code =-1
Unable to install the Security Policy on the appliance
[Expert@cp-xxx01]#
All of these appliances are running R81.10.00 - Build 575. I know that R81.10.08 - Build 683 is recommended release. Update is planned but it will take a serious amount of time, because update has to be coordinated with every single location.
So, at the moment I have to deal with R81.10.00. I found out that other 1530s with this version have no problems. And I know that there exists a problem with partition /pfrm2.0 filled above 85 % on R77.20.x (sk126372). I cannot find a SK with this limitation for R81.10.x.
But I found that all 1530s with problems have /pfrm2.0 filled above 85 %, the ones working are below this watermark. Since I have problems to get reboot clearance for the systems I would like to know…
- … if anybody there had the same problem with R81.10.x on SMB and solved the problem with reboot – and if only for the moment.
- … if anybody knows if the workaround from sk105217 (fiddeling with IPS protections) will do the job. I have little doubt on this because other 1530s are running without implementing the workaround and I do not want to weaken IPS.
- … if anybody knows if the workaround from sk126372 (setting a link for $FWDIR/state/__tmp/FW1 to /storage partition) will also work for R81.10.x. The parameter in the advanced settings exists but the SK only mentions R77.20. I implemented this to all 1430s.
Any help will be appreciated.
Thanks in advance,
Oliver