Cisco :: LMS 4.2.2 / Can Exclude Device From Config Archive
Oct 17, 2012
I have a number of devices such as Cisco Call Manager, or Cisco Wireless Controllers, etc that I want to remain in DCR but would like to exclude from the Config Archive process. Is there any way of excluding an individual device from this process?
We are currently running Cisco prime 4.1 and want to make sure there is a backup of the configurations from our switches and routers. The VLANconfig is not collected according to the devicestatus dashboard. i am aware there were a known issue with LMS running on a virtual server and vlan not being able to be collected, is this issue resolved? i have tried the various workarounds with TAC support and it hasnt worked. We have the running and startup config collected for our devices when looking at the device status dashboard. does this mean if a switch crashes we can restore the config to a new switch immediately?
i saw there is a version 4.2. maybe this version resolves the issue with LMS on a virutal server? i cannot find the download to upgrade to 4.2 in the support section though.
I have recovered some configuration files from my 2950 switches with the Configuration Archive Tool in LMS. Now, I'd like to replace my old 2950s by 2960 switches, which have the same number of ports.
Will there be any issue if I copy the exact same config from 2950 to 2960 ? Will some features not work or is everything interoperable ? Here's an extract of the config :
Global version 12.1 no service pad service timestamps debug date time service timestamps log date time no service password-encryption [ code]....
We have LMS Prime 4.2. I know how to view the running config on a single device. How do I run a report that will pull all the running configs of all my devices in one report? I'd be able to same them as one big pdf or text file. ]
8.4(3) I need to outside PAT all incoming UDP (SIP/RTP) traffic from outside to an internal IP. The following command makes it work:
nat (outside,inside) source dynamic any obj-10.0.0.173 service udp udp
But it breaks DNS resolution from inside. If I add the above command and try to nslookup from inside to an outside DNS server 64.90.175.90, DNS times out. If I remove the above nat command, it works again. It seems like even though DNS UDP originates from inside which should create a statefull connection, ASA still messes with return DNS responses.I then tried to create an "exclusion" for that IP with the following:
ADSL ---> Cisco 877 with connected site-to-site VPN's ---> Cisco ASA 5505 with Remote VPN enabled
I want to connect my Android phone to the Cisco ASA 5505 with Remote VPN. When I forward port 500 and 4500 on the Cisco 877 to the Cisco ASA5505 I can connect with the phone.
But as expected, the site to site connections are lost because now they try to reach the ASA 5505 also.
I want to exclude the site to site external IP addresses from doing static NAT to the ASA 5505...how can I accomplish this ?
I have an inventory added to Ciscoworks and am getting alerts on interfaces that I want to exclude but for the life of me I can't figure out how to exclude interfaces. Any tips on how to exclude interfaces from the fault engine in 4.1.
I'd like to know if there is a way to exclude passed authentications for a specific username from reporting in the Authentications-TACACS and Authentications-RADIUS reports?
We have a few usernames that are used in scheduled jobs. We only need to know when they fail authentication, so we don't need to fill up the reports with every passed authentication from these accounts. Can this be done?
In earlier versions of LMS it was possible to choose i.e. the Routers category (top level) and enter a series of commands to be excluded from the comparison. In LMS 4.0.1 I experience, in several different installations, that this is not possible. It seems I can enter one exclude command beyond the defaults per category, the rest is not applied even though the feedback from the application is positive. Next time I access the Exclude Commands view, the commands I entered are gone. Is this a change of behaviour or a bug?
If i connected the latop to brand new out of the box ASA 5505 through consloe cable and i have a config file on this laptop from other ASA5505, is there anyway i can upload that config file into startup-config of this new ASA5505 through console cable, without using TFTP or FTP?
I have a Cisco 2811 router and when I turn of the router the running config is lost. I have to the following to get the router running of the start-up config settings.
I have configured a SVI in my 4500 ( Sup 7-E 10GE,,,,,,and,,,,,cat4500e-universalk9.SPA.03.02.00.SG.150-2.SG.bin) switch and it is showing Down Down, because there were no active switch port in the vlan, I added one switch port to this vlan but this port also in the down state, so i added the SWITCH PORT AUTO STATE EXCLUDE command under this port, even after this also the SVI never came up, So i added one systen to the port so both the switch port and the SVI came up...So why SWITCH PORT AUTO STATE EXCLUDE command have no effect in this model of the switch..
we have an LMS 3.2 in which it cannot archive the configuration for a couple of routers. The output is the following:
Failed to fetch the configuration. Check the dcmaservice.log for details. TELNET: Failed to establish TELNET connection to x.x.x.x - Cause: connect timed out.
The issue is that i have configured all devices to be accessed through SSH first and then through telnet. I have tested SSH access from LMS with putty.
I have a not-so newly installed LMS4.2 Linux appliance. Here is my configuration archive summary:
Config Archival Status No. of Devices Successful 7 Failed 1338 Partially Successful0 Total1345 Configuration Never Collected 1338
[Code].....
Which seems to mean that SSH does not work, which is false as I manually connects to the device from the LMS host successfully. Network devices access is authenticated against ACS servers using TACACS+ so there should be no problem with credential discrepency here.
I have a question about a daily archive sync job. I have the job set to run by device type groups. My question is, when I delete or add devices, will they automatically be added to the job?
I beleive in the past these devices could not be managed bij RME config management, but now it says in the supported device table:The following features are supported:Network Topology Layer 2 ServicesFault ManagementInventory CollectionConfiguration Deploy Protocols: TELNET, SSH, TFTP, RCPConfiguration Fetch Protocols: TELNET, SSH, TFTP, RCP.The password and enable pasword are correct and simply work when I try a telnet from the server.The gui is not CLI but menu driven.RME just says:TELNET: Failed to establish TELNET connection to 10.1.1.7 - Cause: Authentication failed on device 3 times. PRIMARY-RUNNING config Fetch Operation failed for TFTP. Could not detect SSH protocols running on the device.
I've inherited a server running Ciscoworks LMS 4.0 to manage our plethora of switches. Running 'Configuration > Configuration Archive > Synchronization' against a Catalyst 3750 switch called switch1 successfully retrieved the Running, Startup, and VLAN configs.Running the same command the following day on switch1 failed and returned this in the job execution result:Unable to get results of job execution for device. Retry the job after increasing the job result wait time using the option:Admin > Collection Settings > Config > Config Job Timeout Settings I modified the job result wait time setting to be 600 seconds, tried again and received the same timeout failure. I have also seen this same Failed message on other devices, but have never actually received the configs for them, so I feel switch1 is a better place to start.What are the first things I should check in CiscoWorks for a problem like this? Is there a particular software revision I should be on with LMS 4.0? What timeout value should be used for Archive Synchronization?
I am getting some weir behaviour in my LMS 4.2 setup. I am doing and Archiveupdate job and am receiving a partial success for roughly 1400 devices. Here is some output.
Execution Result: STARTUP CM0057 PRIMARY STARTUP Config fetch SUCCESS, archival failed for xxxxxx Cause: CM0210 Unable to generate processed config Action: Verify that archive exists for device. RUNNING
[code]...
I went on and checked the dcmaservice log file.I found the following entry at the same time of this particulair job
ERROR,[Thread-72920],com.cisco.nm.xms.xdi.pkgs.SharedDcmaIOS.analyzer.IOSConfigletRules,loadRules,42,Could not locate configlet rule file : com/cisco/nm/xms/xdi/pkgs/SharedDcmaIOS/analyzer/IOSConfigletRules.ser [ date taken out ],ERROR,[Thread-72920],com.cisco.nm.rmeng.dcma.configmanager.DeviceArchiveManager,archiveNewVersionIfNeeded,1115,CM0210 Unable to generate processed config
I then searched if I had the IOSConfigletRules.set file on the box. And no it is not there. My question is this the reasson that I have som manny partial sucess archive results?
In our organisation we have multiple Nexus 5000 switches, which Cisco LMS 4.2.2 cannot get the running-config and startup-config from with the Archive Management process. When it does try to get them, I get a error as follows:
*** Device Details for SF-DERA-01 *** Protocol ==> Unknown / Not Applicable Selected Protocols with order ==> TFTP,SSH,SCP
Iam using LMS 3.2. In short, there is 2 type of router, 2800series and 2900series. These device already join to TACACS server. When I try to sync archive I got:
- failed on 2900series - successful on 2800series
I have doing same config (credential, snmp, protocol for sync archive), for those device on ciscoworks but why I find the error??
I'm having trouble syncing the config archive for some of my nodes.
I get the error 'partially successful' (see attatched PNG).
I've looked in the dcmaservice.log (also attatched), and I can see the extended error message:
[ Wed Jan 11 09:49:30 CET 2012 ],ERROR,[Thread-2137],com.cisco.nm.rmeng.dcma.configmanager.DeviceArchiveManager,getLatestConfigFileVersion,168,CM0021: Version does not exist in archive $1 Cause: Version may have been deleted [ Wed Jan 11 09:49:30 CET 2012 ],INFO ,[Thread-2137],com.cisco.nm.rmeng.dcma.configmanager.DeviceArchiveManager,getSysObjectID,425,SYS OID
I would like to check the file structure / permissions, but since I don't know what '$1' refers to, I'm stuck.
On our cisco 3750 switches we can take config backups with the archive command. After every "write mem" it rights the config to our backup server. We would like to do this also for our asa 5520 with version 8.2(2). I also searched in the command reference guide, but I can't seem to find the proper command to do it.
The bootloader used by the device is U-Boot, which is also licensed under the terms of the GPL. Sadly these parts are missing from the source code package provided by D-Link. Therefore I am asking you to add the U-Boot sources to the provided archive or post them here in the forum.
I'm trying to do configuration archiving in Prime Infrastructure 1.2 with a 5508 WLC (7.4).The job always fails (Admin -> Background Jobs) with the following error (see attachement):"SNMP: Failed to establish SNMP connection xxxx - Cause: Device is Unreachable. Check the ReadOnly community string." I double checked the SNMP credentials, they do match. For testing I also added a Public community just for the PI. Same result.Am I missing something?Is this not intended for Wireless Controllers?
I can't install or extract any file or archive downloaded through shared connection from the 1st PC via a LAN ... tried new LAN and tried switch the LANs but doesn't work always a CRC error when extract an archive or file corrupted when install anything downloaded:this is what I tried so far
-tried download and extract on a 2nd installed windows (I have dual boot) and its same CRC error -tried another non built-in LAN card pci-E x1 and its the same CRC error -tried restore bios to default and its same CRC error -tried putting a laptop on the same line instead of my PC and it works no errors no problems