On the Statistics Collection page of the Barracuda Firewall Control Center, you can view the status of statistics collection from each managed Barracuda CloudGen Firewall. If the statistics services malfunction, you can also manually get and recover lost statistics entries from this page.
View the Status of Statistics Collection
- Go to CONTROL
- To get statistics for a specific Barracuda CloudGen Firewall, right-click the system and select Get Statistic.
- To recover a Barracuda CloudGen Firewall, right-click the system and select Recover.
Recovery and State Analysis of Poll Sessions
Error analysis of poll sessions is displayed as follows:
Analysis of Error Scenarios
Cannot connect to box.
Cannot receive transfer files ('toSend.timestamp') from box.
|Cannot perform calculation of statistic file list.|
Received transfer files remain in box-specific state directory and will be ignored in subsequent poll sessions.
|A dist-operation fails. No problem because these operations are transaction protected.|
Data files either be successfully merged or are stored within temporary data directory.
Box state is dirty because a possible synchronization with the HA partner would result in inconsistent data (files in temporary data path won't be synced).
|masterAccept-file cannot be created.|
masterAccept-file cannot be sent.
|Cannot remove temporary data directory (because it's not empty).|
Cannot remove obsoleted state files.
Example - Barracuda Firewall Control Center Statistic HA Sync
When statistics files cannot be synchronized from the Barracuda Firewall Control Center to its HA partner, the following message is recorded in the mirrorstat.log file:
Error ST-ML-RE0002 mirrorstat(x.x.x.x,ARGS): peer x.x.x.x also in state dirty
Error ST-ML-OP0010 mirrorstat(x.x.x.x,ARGS)->1: terminating abnormally, manual intervention required
The mirrorstat is a script file that is executed on a regular basis in order to process synchronization of statistics files between the Barracuda Firewall Control Center and its HA partner over an SSH connection. When the script triggers SSH connection establishment to the Barracuda Firewall Control Center HA partner, it expects the DSA key fingerprint of the HA partner to be known on the Barracuda Firewall Control Center. If the fingerprint is not yet known because an SSH connection between the two systems has never before been established, it cannot be processed any further. In this case, execute the following steps to configure the statistics files synchronization:
- Initiate an SSH connection from the Barracuda Firewall Control Center to its HA partner manually, in order to make the DSA key fingerprint known. At the command line on the Barracuda Firewall Control Center, enter:
ssh -lroot <HA partner IP>
- Delete the synchronization status files in the
/phion0/dstatm/directory on both the primary and the secondary Barracuda CloudGen Firewall. At the command line, enter:
- Go to the of the primary system and restart the dstatm service.