I have a Cisco ACS 5.2 and have set it up as a RADIUS server. I was wondering if there is a way to add and update users automatically? We have a large number of users > 1000 that need to be added into the system and I don't want to do this manually. These users also update their passwords on a regular basis so I would need a script that would update the users automatically without any user intervention.
I purchased 2 RV042's (h/w version 3) less than two months ago. I updated them to the latest firmware (v4.0.4.02-tm (Jul 4 2011 13:30:56)), did a factory reset to make sure I was working with a clean slate, set up DDNS through DynDNS and a site to site VPN between the two. Everything was working great for a month, then the DynDNS accounts expired because they weren't being updated. I reactivated the names on the DynDNS site, and started to monitor the "last updated" date and time. After 24 hours there were no updates according to the DynDNS site. I logged into one of the RV042's, and it said "Dyndns Enabled : Dynamic DNS is updated successfully." This is a stale message from 24 hours ago when I hit save. So I went into Setup | Dynamic DNS | Edit Config and there it also says "Dynamic DNS is updated successfully." I clicked "Save", status changed to " Dyndns Enabled : Updating..." for a few seconds, and then back to "Dyndns Enabled : Dynamic DNS is updated successfully". I refreshed the DynDNS website and it shows the current time (in eastern time, i'm pacfic) as the last time it was updated. So it works when I manually hit the "Save" button. Not making any changed, just hitting "Save". I've let the other RV042 go over 48 hours and it still hasn't updated. So it apears for the time being, I'll have to remember to push the "Save" button once a week to prevent my DynDNS accout from expiring. Does DDNS working in the lastest firmware and h/w version 3? If so, what is the update frequency?
we have an LMS 3.2 in which it cannot archive the configuration for a couple of routers. The output is the following:
Failed to fetch the configuration. Check the dcmaservice.log for details. TELNET: Failed to establish TELNET connection to x.x.x.x - Cause: connect timed out.
The issue is that i have configured all devices to be accessed through SSH first and then through telnet. I have tested SSH access from LMS with putty.
I have a not-so newly installed LMS4.2 Linux appliance. Here is my configuration archive summary:
Config Archival Status No. of Devices Successful 7 Failed 1338 Partially Successful0 Total1345 Configuration Never Collected 1338
[Code].....
Which seems to mean that SSH does not work, which is false as I manually connects to the device from the LMS host successfully. Network devices access is authenticated against ACS servers using TACACS+ so there should be no problem with credential discrepency here.
I have a question about a daily archive sync job. I have the job set to run by device type groups. My question is, when I delete or add devices, will they automatically be added to the job?
I beleive in the past these devices could not be managed bij RME config management, but now it says in the supported device table:The following features are supported:Network Topology Layer 2 ServicesFault ManagementInventory CollectionConfiguration Deploy Protocols: TELNET, SSH, TFTP, RCPConfiguration Fetch Protocols: TELNET, SSH, TFTP, RCP.The password and enable pasword are correct and simply work when I try a telnet from the server.The gui is not CLI but menu driven.RME just says:TELNET: Failed to establish TELNET connection to 10.1.1.7 - Cause: Authentication failed on device 3 times. PRIMARY-RUNNING config Fetch Operation failed for TFTP. Could not detect SSH protocols running on the device.
I've inherited a server running Ciscoworks LMS 4.0 to manage our plethora of switches. Running 'Configuration > Configuration Archive > Synchronization' against a Catalyst 3750 switch called switch1 successfully retrieved the Running, Startup, and VLAN configs.Running the same command the following day on switch1 failed and returned this in the job execution result:Unable to get results of job execution for device. Retry the job after increasing the job result wait time using the option:Admin > Collection Settings > Config > Config Job Timeout Settings I modified the job result wait time setting to be 600 seconds, tried again and received the same timeout failure. I have also seen this same Failed message on other devices, but have never actually received the configs for them, so I feel switch1 is a better place to start.What are the first things I should check in CiscoWorks for a problem like this? Is there a particular software revision I should be on with LMS 4.0? What timeout value should be used for Archive Synchronization?
I am getting some weir behaviour in my LMS 4.2 setup. I am doing and Archiveupdate job and am receiving a partial success for roughly 1400 devices. Here is some output.
Execution Result: STARTUP CM0057 PRIMARY STARTUP Config fetch SUCCESS, archival failed for xxxxxx Cause: CM0210 Unable to generate processed config Action: Verify that archive exists for device. RUNNING
[code]...
I went on and checked the dcmaservice log file.I found the following entry at the same time of this particulair job
ERROR,[Thread-72920],com.cisco.nm.xms.xdi.pkgs.SharedDcmaIOS.analyzer.IOSConfigletRules,loadRules,42,Could not locate configlet rule file : com/cisco/nm/xms/xdi/pkgs/SharedDcmaIOS/analyzer/IOSConfigletRules.ser [ date taken out ],ERROR,[Thread-72920],com.cisco.nm.rmeng.dcma.configmanager.DeviceArchiveManager,archiveNewVersionIfNeeded,1115,CM0210 Unable to generate processed config
I then searched if I had the IOSConfigletRules.set file on the box. And no it is not there. My question is this the reasson that I have som manny partial sucess archive results?
In our organisation we have multiple Nexus 5000 switches, which Cisco LMS 4.2.2 cannot get the running-config and startup-config from with the Archive Management process. When it does try to get them, I get a error as follows:
*** Device Details for SF-DERA-01 *** Protocol ==> Unknown / Not Applicable Selected Protocols with order ==> TFTP,SSH,SCP
Iam using LMS 3.2. In short, there is 2 type of router, 2800series and 2900series. These device already join to TACACS server. When I try to sync archive I got:
- failed on 2900series - successful on 2800series
I have doing same config (credential, snmp, protocol for sync archive), for those device on ciscoworks but why I find the error??
I have a number of devices such as Cisco Call Manager, or Cisco Wireless Controllers, etc that I want to remain in DCR but would like to exclude from the Config Archive process. Is there any way of excluding an individual device from this process?
I'm having trouble syncing the config archive for some of my nodes.
I get the error 'partially successful' (see attatched PNG).
I've looked in the dcmaservice.log (also attatched), and I can see the extended error message:
[ Wed Jan 11 09:49:30 CET 2012 ],ERROR,[Thread-2137],com.cisco.nm.rmeng.dcma.configmanager.DeviceArchiveManager,getLatestConfigFileVersion,168,CM0021: Version does not exist in archive $1 Cause: Version may have been deleted [ Wed Jan 11 09:49:30 CET 2012 ],INFO ,[Thread-2137],com.cisco.nm.rmeng.dcma.configmanager.DeviceArchiveManager,getSysObjectID,425,SYS OID
I would like to check the file structure / permissions, but since I don't know what '$1' refers to, I'm stuck.
On our cisco 3750 switches we can take config backups with the archive command. After every "write mem" it rights the config to our backup server. We would like to do this also for our asa 5520 with version 8.2(2). I also searched in the command reference guide, but I can't seem to find the proper command to do it.
The bootloader used by the device is U-Boot, which is also licensed under the terms of the GPL. Sadly these parts are missing from the source code package provided by D-Link. Therefore I am asking you to add the U-Boot sources to the provided archive or post them here in the forum.
I'm trying to do configuration archiving in Prime Infrastructure 1.2 with a 5508 WLC (7.4).The job always fails (Admin -> Background Jobs) with the following error (see attachement):"SNMP: Failed to establish SNMP connection xxxx - Cause: Device is Unreachable. Check the ReadOnly community string." I double checked the SNMP credentials, they do match. For testing I also added a Public community just for the PI. Same result.Am I missing something?Is this not intended for Wireless Controllers?
I can't install or extract any file or archive downloaded through shared connection from the 1st PC via a LAN ... tried new LAN and tried switch the LANs but doesn't work always a CRC error when extract an archive or file corrupted when install anything downloaded:this is what I tried so far
-tried download and extract on a 2nd installed windows (I have dual boot) and its same CRC error -tried another non built-in LAN card pci-E x1 and its the same CRC error -tried restore bios to default and its same CRC error -tried putting a laptop on the same line instead of my PC and it works no errors no problems
what is the feature option " Proxy ARP on egress interface" used for on the ASA? I'm about to upgrade a ASA from IOS 8.2(1) to 8.4(5) and I am trying to determine if it should be enabled or disabled.
I am using Cisco 3560 POE -WS-C3560CG-8PC-S- switch for my AP's. The current IOS i got on this switch don't allow me to use web console. when i am click on webconsole i am getting attached. what is the best way of removing and installing new IOS.
Last night we upgraded one of our offices 3560 (WS-C3560-24PS) to 12.2(55) SE6. With these switches, NTP is no longer working. The NTP server is a router at this office. Switches at this office that were not upgraded (3750) are getting NTP normally. Below is a copy of the show ntp association and show ntp status. I have removed the ntp lines from the switch configuration and re-added them, and that has not changed anything.
Clock is unsynchronized, stratum 16, no reference clock nominal freq is 119.2092 Hz, actual freq is 119.2092 Hz, precision is 2**17 reference time is 00000000.00000000 (18:00:00.000 CST Thu Dec 31 1899) clock offset is 0.0000 msec, root delay is 0.00 msec root dispersion is 0.00 msec, peer dispersion is 0.00 msec
I enabled NTP debugging for events, packets, and clock synchro.
I tried updating my firmware of my DIR-655 from 1.34NA to 1.35NA (Hardware Version: A1/A2).
However, I found something strange while updating the firmware, that made me stop, in order to ask the question.
Previously, when I did an update, I would browse for the location, and put it in, and it would allow me to update from that location.
Now, it will allow it, but when I select to update from the desktop (C:usersderickdesktop), it comes up with another location (C:fakepath) for the .bin file.
i have an DIR-655 Hardware Version: A4, with Firmware Version: 1.21.Its dated: 2008/11/13.Do i get any improvement updating? And in such case, which FW should i use? It must be rock solid!
I have a Cisco 2921 router running c2900-universalk9-mz.SPA.150-1.M4.bin.Its licensed for ipbase, ipbasek9, Permanent and uc,uck9,Permanent (I'm using the router as a voice gateway),I'm looking to update the IOS to c2900-universalk9-mz.SPA.150-1.M5.bin as I'm told it has a fix for some DSP problems.So the question is, do I need to obtain a new license key to apply this update or am I covered by the existing license on the router.