Before installing the application upgrade package, it is recommended to first create a backup of the current state of each Central Node server to be updated and download it to the hard drive from the application administrator menu. If installing an application upgrade package fails, or if you need to reinstall Kaspersky Anti Targeted Attack Platform, you can use the backup copy of the application.
We also recommend learning about the limitations of the version to which you are upgrading.
The hardware requirements for 7.0 Central Node servers are different from the hardware requirements of the previous version of the component. We strongly recommend making sure that your server configuration satisfies the requirements listed in the Calculations for the Central Node component section.
The upgrade is delivered as an upgrade package. The package is included in the application distribution kit.
If you are using the distributed solution and multitenancy mode, you must complete the steps to prepare for installing the upgrade before proceeding with the upgrade.
All steps described below must be performed on servers in Technical Support Mode after elevating user privileges using the sudo -i
command.
To upgrade Central Node installed as a cluster:
ceph -s | grep health:
The Ceph storage is healthy if the following value is returned:
health: HEALTH_OK
If the value is different from health: HEALTH_OK
, please contact Technical Support.
systemctl restart kata-osd-starter
docker node ls
A list of cluster servers is displayed. Look at the MANAGER STATUS
column in the list: if a server has Leader
or Reachable
in that column, it means it has the 'manager' role.
docker service ps kata_product_main_1_schema_registry
Look at the value in the NODE
column to determine which server has the Schema Registry.
docker exec -it $(docker ps | grep schema_registry | awk '{ print $1 }') curl http://127.0.0.1:8081/subjects
If you get a JSON with a list of subjects, it means the Kafka service is working.
kata-enable-span
If processing of mirrored traffic from SPAN ports is disabled, the upgrade fails.
/data
directory. To view the role, use the $ docker node ls
command.tar xvf /data/kata-upgrade-7.0.3.520-x86_64_en-ru.tar.gz -C /data/
cd /data/upgrade/
./run_kata_upgrade.py
The user name entry window is displayed.
Default value: admin.
This opens the window for entering the path to the update archive.
Default value: /data/upgrade.
Parts of the application related to NDR functionality will be displayed in the selected language.
After some time, the console will display a message prompting you to power off the server.
poweroff
command.A script is started that completes the upgrade process. After the update is complete, the console displays a message telling you to shut down the next server in the cluster.
The last server to be updated is the server to which you connected at step 6. For that server, step 20 is omitted.
The Central Node component is upgraded.
After updating the component, you must log in again to the Central Node server management console over SSH or through the terminal.
If you have upgraded your PCN to version 7.0.3 and do not intend to upgrade the application to version 7.1.1 for six months or more, we strongly recommend applying the fix_old_slots.sh script after the upgrade to avoid overfilling the PCN server disk. You can get the script file and instructions for its use by contacting the Technical Support Service.
Page top