Security Compliance
Import settings from a SIM or SEM manager backup to another manager
Learn how to import settings from a SIM or SEM manager backup to another manager for SEM 5.4 and later.
First published date
Last published date
Overview
This article describes how to import settings from a SIM or SEM manager backup to another manager for SEM 5.4 and later.
Product section
Resolution
Starting with SEM version 5.4, the CMC includes an import command that imports manager settings from any 5.4 appliance backup. After upgrading to SEM version 5.4 or higher, use the import command to do any of the following:
- Migrate a hardware appliance (SIM) to a virtual appliance (SEM).
- Migrate a virtual appliance from one VM server to another.
- Migrate a hardware appliance (SIM) to new hardware.
- Recover settings after a hardware or software failure.
Important: The import command does not work with backup files for versions earlier than 5.4. To complete the following procedure, upgrade all of your appliances to the latest version, and then export a backup of your manager the new version using the backupconfig command.
This is only an import or export procedure of manager configuration settings. Appliance settings like timezone and database restoration are not covered in this procedure.
To migrate your SEM/SIM Manager settings to another appliance (virtual or hardware):
- Upgrade all of your appliances to the latest version and deploy any new appliances.
- Run the
backupconfigcommand on the source appliance as described in the Backup/Export Procedure section. - Shut down the source appliance, or disconnect it from the network.
- Run the
importcommand and change the CMC password on the new appliance as described in the Import Procedures section. - If you are converting a SIM appliance to a SEM appliance, apply the SEM license in the new console, and then reboot the new appliance. For additional information, see Applying Your SEM License File (v5.3+).
Note: If you want to run SEM reports against the source appliance after migrating its settings to a new appliance, reconfigure its network settings and add it as a manager on the SEM reports computer as described under the Additional Information section.
Backup/Export Procedure
For the sake of this article, upgrade your appliance to the latest version before running the backupconfigcommand. The import command discussed in the next section does not work with backups from appliances running versions earlier than 5.4.
To do a one-time backup of your SEM/SIM appliance using backupconfig:
- Connect to your appliance using a virtual console or SSH client.
- Access the CMC prompt:
- Virtual Console: Arrow down to Advanced Configuration, and then press Enter.
- SSH Client: Log in using your CMC credentials.
- At the
cmc>prompt, entermanager. - At the
cmc::cmm#prompt, enterbackupconfig. - Press Enter to start the backup script.
- Enter
5to back up your appliance immediately. - Enter
ythree times.
Note: This procedure only works if you have already scheduled regular backups on your appliance, and the command uses the network share and user information you have already configured.
Import Procedures
After backing up your source appliance on the latest version, complete this procedure to import that backup to your destination appliance.
To import SEM/SIM manager settings from another appliance (virtual or hardware):
- Connect to your appliance using a virtual console or SSH client.
Notes:- If you change the appliance IP address while connected with an SSH client, the appliance terminates your connection after it restarts networking.
- Regardless of the settings you import, the MAC addresses of the two appliances differ. If the source and destination appliances both use DHCP, the destination appliance retains its current IP address lease even after the import.
- Access the CMC prompt:
- Virtual Console: Arrow down to Advanced Configuration, and then press Enter.
- SSH Client: Log in using your CMC credentials.
- At the
cmc>prompt, enterappliance. - At the
cmc::acm#prompt, enterimport. - Press Enter to start the import script.
- Enter and confirm the file location, user account, and password information you want your appliance to use for the import.
Notes:- Enter the file location in UNC format. For example, enter
\\server\share. If your appliance cannot resolve hostnames, use the server's IP address instead. - Provide credentials for a user with read permissions to the share you entered for the import.
- Enter the file location in UNC format. For example, enter
- Enter the number that corresponds to the backup you want to import.
Note: If you do not see the file you are looking for, verify that you entered the file path correctly, and that you exported the backup you are looking for from an appliance running the latest version. Theimportcommand does not work with backups from appliances running versions earlier than 5.4. - Press Enter twice to start the SEM import wizard.
- Verify the import settings, and then select Yes if you want to proceed.
- If you configured Snort IDS on the source appliance, select Yes to import Snort settings and enable Snort on the destination appliance. Otherwise, select No.
Note: Starting with version 5.4, the optional Snort IDS component on the LEM appliance is disabled by default. If you enable Snort here, and you have not configured it previously, see this article to configure Snort on the new appliance. - Select whether you want to import all SEM settings from the backup (Yes) or specify new network settings (No).
At this point, the import wizard branches in two directions. Complete the wizard based on the option you chose in Step 11.
To complete the import wizard and import all settings:
- Select Yes to confirm your selection.
- Press Enter to acknowledge a reboot and finish the import.
- Skip the following procedure and proceed to the Change CMC password section.
To complete the import wizard and specify new network settings:
- Select Yes to specify a Static IP (recommended), and then set the following properties:
- IP Address
- Subnet Mask
- Gateway
- Fully qualified domain name of the DNS domain
- DNS server IP address
- Select whether you want to specify a new hostname for the new appliance (Yes) or accept the hostname from the backup (No).
- If you chose to specify a new hostname, enter the new hostname, observing standard hostname naming conventions.
- If the import wizard hangs at "Updating resolver" for more than a minute, press Enter to force the import wizard to finish.
After you configure the new network settings on the destination appliance, the import wizard takes you back to the CMC interface with the option to export a new SSL certificate. Follow the on screen instructions to export a new SSL certificate if both of the following conditions are true:
- You did not import the hostname from the source appliance backup.
- You plan to install the SEM Console locally on any Windows computers.
If you do not want to export a new SSL certificate or do not need it, press Ctrl+C to stop the export script.
To change the CMC password:
- At the
cmc>prompt, enterappliance. - At the
cmc::acm#prompt, enterpassword. - Press Enter to confirm your entry.
- Enter the default CMC password,
password. - Enter and confirm a new CMC password.
Additional Information
If you want to run SEM Reports against a decommissioned appliance after migrating its settings to a new appliance, complete the following procedure to reconfigure its network settings and add it as a manager on the SEM Reports computer.
To run SEM Reports against a decommissioned SEM/SIM appliance:
swi-lem, swi-lem, default, manager
- Disconnect the decommissioned appliance from the network your new appliance is on.
- Change the network settings for the decommissioned appliance:
- Connect to the decommissioned appliance using a direct KVM connection to the server.
- Log in with your CMC credentials.
- At the
cmc>prompt, enterappliance. - At the
cmc::acm#prompt, enternetconfig. - Press Enter to validate your entry.
- Enter
staticto assign a static IP address (recommended). - Follow the on screen instructions to complete the process.
- Change the hostname for the decommissioned appliance
- At the
cmc::acm#prompt, enterhostname. - Press Enter to validate your entry.
- Enter
yesto acknowledge the warning and proceed. - Enter a different hostname for the decommissioned appliance.
- Enter
yto validate your entry.
- At the
- Open
managers.txtfrom one of the following locations, according to your operating system:- Windows XP and Windows Server 2003:
C:\Documents and Settings\<username/>\Application Data\sim.console\Local Store - Windows Vista, Windows 7, and Windows Server 2008:
C:\Users\<username/>\AppData\Roaming\sim.console\Local Store
- Windows XP and Windows Server 2003:
- Add a new line with the new hostname for the decommissioned appliance in place of
swi-lemin the following example. - Save the file, and then relaunch SEM Reports.
Note: If you do not have managers.txt on the computer you want to use to run reports against the decommissioned appliance, see Configuring SEM Reports.