Overview
This section helps users to configure the High Availability setup for EPP 8.6 console within the network. HA helps ensure continuous availability of the EPP in the event of node failures or other disruptions.
Applicable version: EPP 8.6
Prerequisites
Before configuring HA, ensure the following requirements are met:
- An EPP product key with the HA flag enabled. HA can be enabled only after the product key is activated.
- One floating IP address in the same network as the HA nodes. The IP address must be reserved and not assigned to any other machine.
- Three Ubuntu (24.04.3) machines:
- Node 1: Meets the hardware requirements specified for the EPP license.
- Node 2: Meets the hardware requirements specified for the EPP license.
- Auxiliary node: Lower hardware configuration is sufficient; for example, 2 CPU and 4 GB RAM.
- A fresh server snapshot is recommended before starting the HA configuration.
Set Up Node 1 and Node 2
- On both nodes, update the packages and fix any broken dependencies:
sudo apt update apt --fix-broken install - Install EPP on both nodes and verify that you can log in to the EPP console after activation.
- Install
sshpassif SSH is not already installed:apt install sshpass -y - If prompted, fix broken dependencies:
apt --fix-broken install - Restart both nodes and verify that the EPP console is accessible.
Set Up the Auxiliary Node
Install Ansible
On the Auxiliary node:
- Update the packages and fix broken dependencies:
sudo apt update apt --fix-broken install - Install Ansible Core:
sudo apt install ansible-core - Install
sshpassif SSH is not already installed:sudo apt install sshpass -y - Verify the installation:
ansible --version
Configure UTF-8 Locale
Ansible requires UTF-8 locale encoding.
- Edit the locale configuration:
sudo nano /etc/default/locale - Add or update the following entries:
LANG=en_US.UTF-8 LC_ALL=en_US.UTF-8Alternatively, run:
sudo update-locale LANG=en_US.UTF-8 LC_ALL=en_US.UTF-8 - Verify the configuration:
less /etc/default/locale - Restart the Auxiliary node.
- Verify the Ansible installation:
ansible --version
Configure Ansible
On the Auxiliary node, configure the Ansible settings in:
/etc/ansible/ansible.cfg
If the directory or file does not exist, create it.
Set the following parameters:
[defaults]
log_path = /var/log/ansible.log
host_key_checking = False
You can also disable host key checking for the current session:
export ANSIBLE_HOST_KEY_CHECKING=False
Prepare the HA Automation Package
- Download the HA build from the production repository and place it in the
/rootdirectory. - Extract the package:
tar -xzvf EPP_HA_Config.tar.gzIf the package is provided as a ZIP file, extract it using:
unzip EPP_HA_Config.gz
Configure HA Inventory
The Ansible playbooks and inventory files are available in:
ha_automation/ansible
Navigate to the inventories directory and update the following files:
hosts.inivars.yml
Configure hosts.ini
Update the IP addresses of Node 1, Node 2, and the Auxiliary node for the three-node deployment.
Important: Do not modify the existing host groups, such as
[all_nodes]and[eps_nodes]. Changes to these groups can cause the Ansible playbooks to fail.
Configure vars.yml
Specify the following:
- Floating IP address
- CIDR/subnet mask corresponding to the node network
Use the following command to verify the network configuration and CIDR:
ip a
Ensure that the subnet mask matches the physical IP addresses of the HA nodes.
Run HA Automation
Before running the HA automation, perform the following steps on all three nodes:
apt-get update
apt --fix-broken install
apt-get -y purge unattended-upgrades
systemctl disable --now apt-daily.timer
systemctl disable --now apt-daily-upgrade.timer
systemctl daemon-reload
Wait 15–20 minutes for the systems to stabilize. During this period, background processes such as package updates and snapd updates may run.
Use the following command to monitor system activity:
top
Verify that no process is holding the package manager lock:
sudo lsof /var/lib/dpkg/lock
From the ha_automation/ansible directory on the Auxiliary node, run:
ansible-playbook site.yml -i inventories/hosts.ini --ask-pass
Note: If passwordless SSH is already configured between the Auxiliary node and the other nodes, omit
--ask-pass.
Verify HA Cluster Status
After the automation completes, verify the HA cluster status from any HA node:
pcs status
Ensure that the cluster and its nodes are running as expected.
Configure HA Alerts
HA alerts can be enabled from Node 1 or Node 2 using:
/opt/Seqrite_EndPoint_Security/eps_alert/eps_alert.sh --enable
To disable alerts:
/opt/Seqrite_EndPoint_Security/eps_alert/eps_alert.sh --disable
The alert recipient is configured by Ansible based on the email recipient specified during the EPP installation. The default sender address is code>eps@seqrite.com.
Update Email Alert Configuration
To manually change the alert recipient:
- Open the alert script:
sudo nano /opt/Seqrite_EndPoint_Security/eps_alert/eps_alert.sh - Locate the email configuration under:
if [ "$1" == "--enable" ]; then - Update
email_Recipientwith the required email address.
The email_Sender address is configured by default.
Migrate Existing Clients to EPP 8.6 HA
For migration from EPP 7.6/8.3 to EPP 8.6 HA:
- Configure the HA environment and verify the cluster:
pcs status - Ensure that all HA prerequisites are met.
- From the HA setup, download the Export Tool and use it to export data from the existing EPP environment.
- Import the exported data into the EPP 8.6 HA console.
- From Deployment > EPP 7.6 Migration, download the SSP Client Migration Tool from the HA setup.
- Run the SSP Client Migration Tool on the EPP 7.6 server to migrate the clients.
Note: For Windows 7 client machines, ensure that Internet Explorer 11 is installed on the EPP 8.3 Server Client before running the SSP Client Migration Tool on the EPP 7.6 server.