This section provides step-by-step instructions for disaster recovery of EPP server through the backup and restore process. It ensures that you can maintain your previous setup without data loss. It is recommended to perform backup and restore activities every 15 to 30 days.
Prerequisites
- EPP Server Agent script is located at:
/opt/Seqrite_EndPoint_Security/eppserveragent/epp-serveragent.sh - Ensure that you have at least 10 GB of free disk space before starting the backup. (depending on the size of your backup data)
- Ensure that the following files are placed at:
bash epp-serveragent.sh – – backup true – – path /mnt
- eppserveragent.jar
- agent-command.bash
- For distributed backup and restore, perform the following operations on the secondary server.
- If you restore the backup on a different physical machine, reset the AFG flag. In a multi-site deployment, if the available license capacity is exhausted, contact the Activation Team for assistance.
Prerequisites for Distributed Setup
Prerequisites for distributed setup for taking backup and restore.
-
Login to DB server with root user
-
Check if following files are present with this command:
ls -l ~/.ssh/id_rsa ~/.ssh/id_rsa.pub -
If not present , run following commands:
mkdir -p ~/.sshchmod 700 ~/.sshssh-keygen -t rsa -b 4096 -N "" -f ~/.ssh/id_rsa -
Check if the identity added:
eval "$(ssh-agent -s)"ssh-add ~/.ssh/id_rsa -
Certify if it is added :
ssh-add -l -
Use this command to copy the files:
ssh-copy-id -o StrictHostKeyChecking=no -i ~/.ssh/id_rsa.pub root@xxx.xx.xx.xxx (ip of the app server)It will ask the password only once.
-
Now try logging into the machine, with:
"ssh -o 'StrictHostKeyChecking=no' 'root@xxx.xx.xx.xxx'"and check to make sure that only the key(s) you wanted were added.
-
Verify if u can login to that machine without giving password.
Schedule Backup Procedure
This section describes how to configure an automated weekly/monthly backup job for the Seqrite EPP Server Agent, writing backup data to any location on Ubuntu machine or on mounted location on Windows or Linux.
Step 1: Create the Backup Script
-
Open a new script file in the cron.weekly/cron.monthly directory as required:
bash
sudo nano /etc/cron.weekly/eppbackup -
Paste the following content:
\#!/bin/bash LOGFILE="/opt/Seqrite_EndPoint_Security/eppserveragent/backup.log" cd /opt/Seqrite_EndPoint_Security/eppserveragent || exit 1 echo "$(date): Starting backup..." >> "$LOGFILE" echo "" | bash epp-serveragent.sh --backup true --path /mnt/backup >> "$LOGFILE" 2>&1 echo "$(date): Backup finished." >> "$LOGFILE" -
Save and exit:
- Press
Ctrl+O, thenEnter(save) - Press
Ctrl+X(exit)
- Press
Step 2: Make the Script Executable
bash
sudo chmod +x /etc/cron.weekly/eppbackup OR
bash
sudo chmod +x /etc/cron.monthly/eppbackup
Step 3: Check the Backup Log
bash
tail -n 50 /opt/Seqrite_EndPoint_Security/eppserveragent/backup.log
Note:
- The filename
eppbackupmust NOT contain a dot (e.g., no.shextension).
Manual Procedure for Backup and Restore
Backup Procedure
To back up server data, follow these steps:
- Execute the following backup command in Command Prompt:
- Verify Backup Completion.
- Ensure backup files are created in the specified backup folder (C: / Users/ Administrator/ Desktop). The folder consists of these files:
- outputFilePath.txt
- featurepolicies.json
- exportDump (folder)
- mongoDump (folder)
- SRV (for collect logs and CQM uploads – Optional)
- Ensure the command completes without errors.
- A message is displayed "Data backup completed
Location:
/opt/Seqrite_EndPoint_Security/eppserveragent/
Command:
bash epp-serveragent.sh --backup true --path /path
Installation of New Server
Install EPP Server
- Install EPP Server on the same or different machine (with same IP) and perform basic configurations.
- Ensure all installation prerequisites are met before proceeding.
Note: DO NOT perform activation before restore procedure.
Restore Procedure
To restore the backed up server data, follow these steps:
- Copy the Backup folder anywhere you want. (for example, /mnt)
- Execute the following restore command from this location:
Location: /opt/Seqrite_EndPoint_Security/eppserveragent/
Command:
bash /epp-serveragent.sh --restore true --path /path - Verify Restore Process.
Activation
- Now activate the server with the same key used for the previous EPP server installation.
- Confirm that the restore process completes successfully and data is correctly loaded.
- Review application behavior after restoration.
Note: If the backup is restored on a different machine:
- Reset the AFG flag in the activation database before proceeding with activation.
- Reconfigure the patch server.
- In a multi-site setup, although the backup is restored successfully, logs from the earlier default client are not retained. Only the logs generated after the deployment and restoration are available for access.
Mandatory Parameters Explanation
Each command requires these parameters, in the following order:
- Operation Flag
- – – backup for backup
- – – restore for restore
- Boolean Operation Value
- true > Required for both backup and restore
- Path Flag
- – – path
- Backup/Restore Folder Path (example /mnt)
Best Practices
- Run commands from the folder containing the .jar and .bash files.
- Ensure the backup location has full read and write permissions.
- Store backups in multiple locations.
- Validate system functionality after restoration.