System Maintenance
using the system maintenance pages you can use the system > maintenance pages to perform the following tasks enable system maintenance options, such as software version monitoring and disk clean up upgrade, downgrade, or rollback the system software download client installer files so that you can distribute them in out of band methods to end users test network connectivity between the system and servers that have been configured to be used with it display hardware status configuring system maintenance options you can use the maintenance options page to enable various system maintenance features to enable various system maintenance features select maintenance > system > options to display the maintenance options page select options as described in the following table save the configuration the following table lists the system maintenance options configuration guidelinese options guidelines automatic version monitoring if you enable this option, the system reports to ivanti the following data machine identifier information describing your current software, including software build number and build name an md5 hash of your license settings an md5 hash of the internal interface ip address if this node is in a cluster, the number of nodes within that cluster current state of the node cluster type (active/active, active/passive) total number of unique subnets on the cluster nodes version of ivanti secure access client version of esap cluster log synchronization status total number of concurrent users on the device number of ivanti tunnels we strongly recommend that you enable this service gzip compression connect secure only use gzip compression to reduce the amount of data sent to browsers that support http compression this can result in faster page downloads for some users kernel watchdog enables the kernel watchdog that automatically restarts the system under kernel deadlock or when kernel runs low on some key resources enable the kernel watchdog only when instructed by technical support resource throttling enables system resource throttling in the system that gives system processes higher priority high priority processes will get high resources under system load changing this option will cause a system reboot file system auto clean enables the system to automatically clean up the file system when disk utilization reaches 90% the clean up operation deletes files that might be relevant in debugging for example, debug logs, core files, and snapshots might be deleted web installation and automatic upgrade of ivanti secure access client after you deploy ivanti secure access client software to endpoints, software updates occur automatically a ivanti secure access client can receive updates from the server if you upgrade the ivanti software on your ivanti server, updated software components are pushed to a client the next time it connects a bound endpoint receives connection set options and connections from its binding server, but it can have itsivanti secure access client software upgraded from any ivanti server that has the automatic upgrade option enabled during a client software upgrade the client loses connectivity temporarily enable ivanti secure access clientcomponents removal tool for cert issue remediation provides an option for the admin to enable users to download the ivanti secure access client components removal (ivanti upgrade helper) tool on windows end user machines upon browser access and remediates the certificate expiry issue for more information, refer kb44781 https //forums ivanti com/s/article/kb44781 and kb44810 https //forums ivanti com/s/article/kb44810 virtual terminal console enables the virtual terminal on a virtual appliance clear this check box to use the serial console changing this setting will restart the system java instrumentation caching connect secure only caches the java instrumentation to improve the performance of java applications show auto allow connect secure only the auto allow option provides the means to automatically add bookmarks for a given role to an access control policy, for example, web bookmarks with auto allow set are added to the web access control policy you only use this feature if you also use resource policies we recommend that you use resource profiles instead do not show task guidance/help page on admin login this option is applicable only in case there are no licenses installed when enabled, task guidance/help page does not appear automatically upon administrator login clear all configuration data at this device this option clears all keys and triggers a configuration reset and reboots the device prevent system overload disallows user login, user login via ivanti secure access client, html5 connection or connection to a web resource when the cpu load is above a certain threshold by default, this option is disabled for ics upgrades and enabled for new installation exception admin logins, dmi and inbound rest calls are not blocked due to cpu overload when a login to the html5 connection or connection to a web resource is blocked and when a user tries to log in, the login page will display an appropriate system busy message to configure log events for user access, in the system > log/monitoring > user access > settings tab, select the system too busy check box by default, this option is enabled select system > log monitoring > user access > log to view the logs auto reboot the system this option automatically reboots the system when the appliance is in kernel panic state monitor saml server processes enabling this checkbox, saml server instance(s) gets monitored for high memory usage and kills if it consumes more than 3 5gb of virtual memory monitor web server processes enabling this checkbox, web server instance(s) gets monitored for high memory usage and kills if it consumes more than 3 5gb of virtual memory sample event and ids id='sys32251' or id='sys32252' or id='sys32253' or id='sys32254' enable browser extension enabling this psal, follows browser extension path psal state timeout specify timeout in minutes max is 9 minutes, min is 2 minutes end user localization select one of the following options automatic (based on browser settings) english (u s ) chinese (simplified) chinese (traditional) french german japanese korean spanish external user records management persistent user records limit specify the maximum number of user records this feature is useful when system performance is affected due to a large number of user records we highly recommend you consult technical support prior to using this feature deleting a user record removes all persistent cookies, sso information, and other resources for that user it does not remove the user record from the external or internal authentication server if you delete a user record and that user logs back in to the authentication server, new user records are created records are not removed if that user is currently logged in number of records to delete when the limit is exceeded specify a number older records are removed first a user record is not deleted if that user is currently logged in delete records now check whether the persistent user records limit has been exceeded if it is, delete the number of user records specified in the option above automatic deletion of user records periodically check whether the persistent user records limit will be exceeded whenever a new user record is about to be created if true, delete the records prior to creating the user new record upgrading the system software this topic describes how to upgrade, downgrade, and rollback the system software downloading a software package to download a software package go to product download page https //forums ivanti com/s/product downloads?language=en us and browse to the software download page for your product when prompted, log in with your ivanti customer username and password accept the license agreement when prompted, save the software package to your local host uploading a software package you can upload a software package to the system without immediately initiating the upgrade process this is known as staging the upgrade you can stage one package uploading a second package overwrites the previous staging to upload a software package select maintenance > system > upgrade/downgrade to display the system software maintenance page the following figure shows ivanti connect secure under managed staged service package , select upload new package into staging area and use the browse button to locate and select the service package file click submit to upload the file the upload status window shows the progress of the upload operation software upgrade page if you have enabled logging for administrator changes (system > log/monitoring > admin access > settings page), a log is written to the admin access logs page upgrading the system software installing a service package can take several minutes and requires the system to reboot because existing system data is backed up during this process, you can decrease installation time by clearing your system log before trying to install a service package when the system software is upgraded latest set of trusted server cas are uploaded these new set of trusted server cas will be seen in the system > configuration > certificates > trusted server cas page any expired certificates in the default trusted server ca store are removed from the system when the system software is upgraded to 22 7r2, it automatically upgrades ivanti connect secure to openssl version 3 0 9 to upgrade the operating system select maintenance > system > upgrade/downgrade to display the system software maintenance page software upgrade status page docid sbmmp2ziqz4s039adb4v shows the system software maintenance page under install service package, select one of the following options to proceed from file use the browse button to locate and select the service package file from staged package select the service package file that was previously uploaded do not select the deletes option when you are upgrading software the deletes option is available to support downgrading software click install the system displays the service package installation status page, which provides a summary of the integrity checks and compatibility checks and other status indicators software upgrade status page if you have enabled logging for administrator changes ( system > log/monitoring > admin access > settings page), a log is written to the admin access logs page if you have enabled logging for system status (system > log/monitoring > events > settings page), logs are written to the events logs page downgrading the system software if necessary, you can downgrade to an earlier version of the system software when you downgrade, you must clear the system and configuration data to avoid unexpected behavior that can occur when the system has data that relates to the newer software if you downgrade the system, you must reestablish network connectivity before you can reconfigure it to downgrade the operating system select maintenance > system > upgrade/downgrade to display the system software maintenance page system maintenance platform page docid sbmmp2ziqz4s039adb4v shows the system software maintenance page under install service package, select one of the following options to proceed from file use the browse button to locate and select the service package file from staged package select a service package file that was previously uploaded select the deletes option to delete all system and user configuration data before installing the service package, restoring the member to an unconfigured state click install rolling back the system software if necessary, you can roll back the system to the previous software version and configuration state the system is rebooted and unavailable for a few minutes when you roll back to roll back the operating system select maintenance > system > platform to display the system maintenance platform page system maintenance platform page docid sbmmp2ziqz4s039adb4v shows the system maintenance platform page for ivanti connect secure click rollback system maintenance platform page the rollback option appears only if you have previously upgraded the system software if you have enabled logging for system status (system > log/monitoring > events > settings page), logs are written to the events logs page downloading client installer files you can use the system maintenance client installers page to download client installer files the downloadable files include exe and msi files for use installing clients on windows platforms, and dmg files for installing clients on macintosh platforms to download client installer files select maintenance > system > installers to display the client installer files page system maintenance client installers page ivanti connect secure docid sbmmp2ziqz4s039adb4v shows the client installer files for ivanti connect secure click download to download the file to your local host system maintenance client installers page ivanti connect secure restarting, rebooting, and shutting down the system you can use the admin console to perform restart, reboot, and shut down operations the following items explain these terms restart kills all processes and restarts the system the system is available again after a few minutes reboot power cycles and reboots the system the system is available again after a few minutes shut down shuts down the system the system is not available again until the physical power button on the physical device is used to restart the system the restart, reboot, and shutdown operations are applied to all enabled members of a cluster if you do not want to apply the operations to all members of the cluster, use the system > clustering > status page to disable members; then perform the restart, reboot, or shut down operation to restart, reboot, or shut down the system select maintenance > system > platform to display the system maintenance platform page system maintenance platform page docid sbmmp2ziqz4s039adb4v shows the system maintenance platform page for ivanti connect secure click the desired node operation restart services reboot shut down system maintenance platform page if you have enabled logging for administrator changes (system > log/monitoring > admin access > settings page), a log is written to the admin access logs page if you have enabled logging for system status (system > log/monitoring > events > settings page), logs are written to the events logs page testing network connectivity you can use the admin console to test network connectivity to all the servers with which the system is configured to communicate, for example network services or aaa servers to test network connectivity select maintenance > system > platform to display the system maintenance platform page system maintenance platform page docid sbmmp2ziqz4s039adb4v shows the system maintenance platform page for ivanti connect secure click test connectivity server connectivity results are highlighted in the figure system maintenance platform page
