I haven't played with this at all, but I don't think the agent will make a connection to the backup manager until it notices that the first manager isn't there anymore.
On Tue, Jan 25, 2011 at 9:06 AM, ItsMikeE <[email protected]> wrote: > Following on from the discussions in this topic I have attempted to set up a > high availability solution. > > All servers are running RHEL 5 > I had a working ossec master with /var/ossec on a separate filesystem. > For the moment RIDS is still enabled. > > On a 2nd server I installed the ossec master software, then removed > everything under /var/ossec, and stopped ossec processes from starting > automatically on reboot. > A mirror was created for the filesystem containing /var/ossec between the > master and the 2nd master. > I stopped ossec on primary master, made sure the mirrors were up-to-date, > broke the mirrors and mounted the mirror on the new master. > On one of my agents I amended ossec.conf to have two IP addresses > <ossec_config> > <client> > <server-ip>original_master_IP</server-ip> > <server-ip>new_master_IP</server-ip> > </client> > </ossec_config> > > I then restarted ossec on the agent, and started ossec on the new master. > > I have not been able to establish any communications between the agent and > the new master. > The UDP 1514 port is open (checked using nmap). > > I tried re-starting the agent from the new master > > ./agent_control -R 009 > 2011/01/25 14:02:17 agent_control(1210): ERROR: Queue '/queue/alerts/ar' not > accessible: 'Connection refused'. > 2011/01/25 14:02:17 agent_control(1301): ERROR: Unable to connect to active > response queue. > > ** Unable to connect to remoted. > > Can anyone suggest where the problem is? >
