Cisco Tomcat service hung on CUCM publisher

Hi,
I have CUCM v7.1.5.32900-2.
The web interface became unreachable, restarted Cisco Tomcat service fixed it.
Does anyone know why it happened and what can be done to mitigate future occurrence.
CUCM Cisco Tomcat Security log:
==============================
2014-06-02 08:09:42,819 ERROR [http-8443-9] impl.DatabaseAccessor - updateLastSuccessfulLoginTime: Failed to execute execute procedure ImsUpdateSuccessfulLoginTime
2014-06-02 08:09:45,691 DEBUG [DefaultQuartzScheduler_Worker-7] impl.AuthenticationDB - Constructor: 
2014-06-02 08:09:51,808 ERROR [http-8443-9] impl.DatabaseAccessor - updateLastSuccessfulLoginTime: Exception Can't load driver java.lang.reflect.InvocationTargetException
2014-06-02 08:09:57,947 ERROR [http-8443-9] impl.AuthenticationDB - authenticateUser: Failed to execute reset last login timeCan't load driver java.lang.reflect.InvocationTargetException
2014-06-02 08:10:43,980 ERROR [http-8443-9] authentication.AuthenticationImpl - loginUtil: SQLException occured. Throwing IMSexception.
java.sql.SQLException: Can't load driver java.lang.reflect.InvocationTargetException
at com.informix.util.IfxErrMsg.getLocSQLException(IfxErrMsg.java:494)
at com.informix.jdbc.IfxDriver.connect(IfxDriver.java:271)
at java.sql.DriverManager.getConnection(DriverManager.java:582)
at java.sql.DriverManager.getConnection(DriverManager.java:207)
at com.cisco.ccm.dbl.Connector.getConn(Connector.java:671)
at com.cisco.ccm.dbl.Connector.connect(Connector.java:588)
at com.cisco.ccm.dbl.Connector.connect(Connector.java:530)
at com.cisco.ccm.dbl.Connector.createTemporaryStatement(Connector.java:851)
at com.cisco.ccm.dbl.Connector.execute(Connector.java:953)
at com.cisco.security.ims.impl.DatabaseAccessor.updateLastLoginTime(DatabaseAccessor.java:943)
at com.cisco.security.ims.impl.AuthenticationDB.authenticateUser(AuthenticationDB.java:253)
at com.cisco.security.ims.authentication.AuthenticationImpl.loginUtil(AuthenticationImpl.java:146)
at com.cisco.security.ims.authentication.AuthenticationImpl.login(AuthenticationImpl.java:74)
at com.cisco.platform.realm.Realm.authenticate(Realm.java:109)
at com.cisco.platform.valve.BasicAuthenticationValve.authenticate(BasicAuthenticationValve.java:219)
at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:528)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:555)
at org.apache.catalina.authenticator.SingleSignOn.invoke(SingleSignOn.java:394)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:298)
at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:857)
at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:588)
at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:489)
at java.lang.Thread.run(Thread.java:619)
Caused by: java.lang.reflect.InvocationTargetException
at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:39)
at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:27)
at java.lang.reflect.Constructor.newInstance(Constructor.java:513)
at com.informix.jdbc.IfxDriver.connect(IfxDriver.java:254)
... 24 more
Caused by: java.lang.OutOfMemoryError: Java heap space
=============================================
Checked Cisco Tomcat Service logs from RTMT, noticed following in Tomcat Manager Logs:
========================================================
Jun 2, 2014 8:00:24 AM org.apache.catalina.core.StandardWrapperValve invoke
SEVERE: Servlet.service() for servlet Manager threw exception
java.lang.OutOfMemoryError: Java heap space
Jun 2, 2014 8:00:27 AM org.apache.catalina.core.StandardWrapperValve invoke
SEVERE: Servlet.service() for servlet Manager threw exception
java.lang.OutOfMemoryError: Java heap space
======================================

Thank you Sreekanth
Did not find anything interesting about memory in System and Application logs.
admin:utils core active list
      Size         Date            Core File Name
=================================================================
 299252 KB   2014-04-18 19:39:50   core.28338.11.cef.1397864390
 118156 KB   2012-11-17 02:00:36   core.13997.6.cimlistener.1353135636
 118284 KB   2011-10-29 03:04:30   core.14005.11.cimlistener.1319871870
 603908 KB   2013-09-07 02:07:57   core.18107.11.cef.1378534077
 368192 KB   2014-02-03 05:14:23   core.25216.11.cef.1391422462

Similar Messages

  • Cisco Tomcat service failure to start in CUCxn 8.5.1

    Hello CSC Team,
    I am experiencing a problem with Cisco Unity Connection 8.5.1 where Cisco Tomcat service does not want to start resulting in web access to Unity Connection also not working show an error message like this "Internet Explorer cannot display the webpage"
    The Cisco Tomcat service keeps on showing the following when I try to start it;
    Cisco Tomcat [Starting]
    Cisco Tomcat [Starting]
    Cisco Tomcat [Starting]
    Cisco Tomcat [Starting]
    Cisco Tomcat [Starting]
    Cisco Tomcat [Starting]
    Cisco Tomcat [Starting]
    Cisco Tomcat [Starting]
    Any ideas why the Cisco Tomcat service wouldn't start?
    Thank you,
    Sibusiso.

    You need to check the following outputs from the affected server
    show status  --------------to check for any unusual memory / disk usage
    utils diagnose test   ----------- check dns, tomcat , ntp etc
    utils core active list --------------- to see if any core dumps have been generated
    If there are any core dumps or any errors in diagnose test command then it will need to be analyzed further for the exact cause of the issue.
    HTH
    Manish

  • Cant access serviceability from one CUCM server to the next

    If I log into my pub and serviceability, I try to access my other subs. I keep getting an error when trying to access the other servers from the drop down list. Although, everything is replicating throughout the cluster, I can log into another CUCM and only use serviceability for that one server also.
    Im going to do a reset tonight on the cluster. the logs are clean and clear on RTMT on all servers. It's very odd. I thought maybe a security password would be wrong, but there are no errors anywhere on any server in the cluster.

    Hi,
    there is a bug associated to this issue
    Unified Serviceability Tools can not connect to other nodes
    CSCud67438
    Description
    Symptom:
    Cisco Unified Serviceability pages Tools -> Service Activation or Control Center Feature or Network Services can not connect to other nodes in the cluster.When another node is selected the Status indicates Connection to the Server cannot be established (Unknown Error)
    Conditions:
    CCMService Tomcat logs indicates the following error message when attempting to connect to other nodes in the cluster,
    {http://xml.apache.org/axis/}stackTrace:javax.net.ssl.SSLException: Certificate not verified.
    Workaround:
    We have the following workarounds
    - Accessing SUB serviceability pages directly
    - Restarting tomcat on PUB ( once ) after the upgradeFor SNMP configuration where same Community string needs to be added or modified on all nodes, again using a Subscriber node instead of the Publisher also seems to work in this case.
    regds,
    aman

  • Cisco CM services restart spontaneously

    Hi All,
    Please can anyone advise what can be the cause the Cisco CallManager services restart spontaneously?
    We are running cucm version 7.0.2. Yesterday we noticed the Cisco CallManager services stopped on the puplisher, so we restarted the services. Since that time the services restarted several times spontaneously. We also have one a subscriber in the claster which is working fine.
    Any ideas?
    Many thanks
    Marian

    Hi Mateusz,
    Thanks for suggestion. I have run the command and it looks very much like this bug 
    "CSCte50152 : Memory leak in CCM due to Transient SIP Connections"
    However, I don't see the line "operate new" which results in memory leak as suggested in "Trouble shooting core dump " section of CISCO FORUM.
    Could you please have a look at this backtrace and further advise ?   Thanks in advance.
     backtrace
     ===================================
     #0  0x001db7a2 in _dl_sysinfo_int80 () from /lib/ld-linux.so.2
    #1  0x00fc67a5 in raise () from /lib/tls/libc.so.6
    #2  0x00fc8209 in abort () from /lib/tls/libc.so.6
    #3  0x0042e53b in __gnu_cxx::__verbose_terminate_handler () from /usr/local/cm/lib/libstlport.so.5.1
    #4  0x0042c251 in __cxxabiv1::__terminate () from /usr/local/cm/lib/libstlport.so.5.1
    #5  0x0042c286 in std::terminate () from /usr/local/cm/lib/libstlport.so.5.1
    #6  0x0042c3cf in __cxa_throw () from /usr/local/cm/lib/libstlport.so.5.1
    #7  0x00a30860 in xercesc_2_7::XMLString::parseInt () from /usr/local/cm/lib/libxerces-c.so.27
    #8  0x09be13ae in XMLDoc::extractElement (node=0xb3d16460, elementName=0xa872d5c, targetVal=@0x6, required=true) at XMLDocHelper.cpp:458
    #9  0x09be3b8d in RemoteCCDataPassthroughRequest::decode (node=0xb3d16460) at XMLDocHelper.cpp:1582
    #10 0x09be5bdc in RemoteCCRequest::decode (node=0xb3d16380) at XMLDocHelper.cpp:731
    #11 0x09be60bf in XMLDoc::decode (buf=) at XMLDocHelper.cpp:322
    #12 0x0959b016 in SIPStationD::processRemoteCcRequest (this=0xb3a18aa8, signal=@0xb3926b60, addr=@0x2a33d20, msg=@0x2a33e70) at ProcessSIPStationD.cpp:13531
    #13 0x0959c2b3 in SIPStationD::wait_SIPReferInd (this=0xb3a18aa8, s=@0xb3926b60) at ProcessSIPStationD.cpp:4098
    #14 0x095b548c in SIPStationD::fireSignal (this=0xb3a18aa8, sdlSignal=@0xb3926b60) at /vob/ccm/Common/Include/Sdl/SdlProcessBase.hpp:174
    #15 0x09e4a050 in SdlProcessBase::inputSignal (this=0xb3a18aa8, rSignal=0xb3926b60, traceType=SdlSystemLog::SignalRouterThread, highPriority=0, normalPriority=0, lowPriority=0, veryLowPriority=0, lazyPriority=0, dbUpdatePriority=0) at SdlProcessBase.cpp:396
    #16 0x09e51e12 in SdlRouter::callProcess (this=0xde568e0, _sdlSignal=0xb3926b60, _deleteSignal=@0x2a34d97, _traceType=SdlSystemLog::SignalRouterThread, _hp=0, _np=0, _lp=0, _vlp=0, _lzp=0, _dbp=0) at SdlRouter.cpp:372
    #17 0x09e51837 in SdlRouter::scheduler (sdlRouter=0xde568e0) at SdlRouter.cpp:282
    #18 0x006b1ef3 in ACE_OS_Thread_Adapter::invoke (this=0xeec3e00) at OS_Thread_Adapter.cpp:94
    #19 0x00672abf in ace_thread_adapter (args=0x0) at Base_Thread_Adapter.cpp:137
    #20 0x004ae371 in start_thread () from /lib/tls/libpthread.so.0
    #21 0x01066ffe in clone () from /lib/tls/libc.so.6

  • NAC-L2-802.1x (EAP-FAST) and Cisco Secure Services Client 5.0 in wired net

    Hi!
    (Sorry, if this is a wrong forum.)
    Does anybody have any success with Cisco SSC and EAP-FAST in the wired network?
    I'm going to use NAC, so I'm trying to set up EAP-FAST. I see the pop-up window on the client to enter user credentials and I see a lot of "debug radius" messages on my 3750 12.2(44)SE switch:
    Access-Requests with User-Name="anonymous"
    Access-Challenges (I see certificate is sent from ACS)
    Access-Reject
    CS ACS Failed Attempts Report shows "ACS user unknown" failure for "anonymous".
    So far as I understood, EAP-FAST is a tunneled method and it uses "anonymous" to protect user's identity during phase 0 / phase 1 transactions. The actual username is sent in phase 2 transaction.
    The following is excerpt from the CS ACS documentation:
    "EAP-FAST can protect the username in all EAP-FAST transactions. ACS does not perform user authentication based on a username that is presented in phase one; however, whether the username is protected during phase one depends on the end-user client. If the end-user client does not send the real username in phase one, the username is protected. The Cisco Aironet EAP-FAST client protects the username in phase one by sending FAST_MAC address in place of the username. After phase one of EAP-FAST, all data is encrypted, including username information that is usually sent in clear text."
    SSC 5.0 is indeed set up with "Unprotected Identity Pattern"=anonymous and "Protected Identity Pattern"=[username] using sscManagementUtility.exe
    So, the question is: Why is ACS 4.1 trying to authenticate username "anonymous" if it knows that the user is fake? Does anybody have working configuaration for EAP-FAST in a wired network?
    Any help is greatly appreciated.

    Correct, ACS database wasn't selected on the NAP Authentication page. It works now, but I constantly get the following message in the Windows event log: "The Cisco Secure Services Client service hung on starting". This is Windows 2000 Advanced Server system with SP4. SSC was set up with no domain authentication, no machine authentication, single sign-on. After some time the SSC service starts, but at that time my PC is already put into the guest VLAN by the switch (the tx-period is 10 seconds):
    POD1-SW#sh run int fa1/0/1
    Building configuration...
    Current configuration : 378 bytes
    interface FastEthernet1/0/1
    switchport access vlan 999
    switchport mode access
    dot1x mac-auth-bypass
    dot1x pae authenticator
    dot1x port-control auto
    dot1x timeout reauth-period server
    dot1x timeout tx-period 10
    dot1x reauthentication
    dot1x critical
    dot1x critical recovery action reinitialize
    dot1x guest-vlan 91
    dot1x critical vlan 11
    spanning-tree portfast
    end
    After all the VLAN is reassigned by the switch, but the delay is too high. How can I troubleshoot this?
    Thx.

  • Component is not running, Cisco Tomcat NotRunning

    I loaded Unity Connection in VMware, and I can't access the Unity Connection GUI. Any idea why?

    Try to solve some network problems with commands
    set network ...  Particilarly, start stop nic with set network status eth0 down/up
    Then try again Start service with utils service start Cisco Tomcat
    See also utils sevice restart Connection DB

  • Unity Connection 9.1 - Tomcat service keeps shutting down

    Hello,
    We are running two Unity Connection 9.1.2TT1.11900-2TT1 servers in a cluster.  We are noticing that 4-5 times a week Cisco Tomcat servce shutsdown.  This is causing issue when our users try to use Cisco PCA.
    The following alert is being generated;
    From Sat Jan 18 01:18:42 EST 2014 to Tue Jan 21 14:46:15 EST 2014 on node 10.24.11.50,
    there are 1 TotalProcessesAndThreadsExceededThresholdStart alarm(s) and 0 TotalProcessesAndThreadsExceededThresholdEnd alarm(s) received.
    On Tue Jan 21 14:46:07 EST 2014, the last TotalProcessesAndThreadsExceededThresholdStart alarm generated:
    NumberOfProcesses : 218
    NumberOfThreads : 1793
    Reason : Total processes and threads have exceeded the maximum tasks [2000]
    ProcessWithMostInstances : Process [unityoninit] has instances [35]
    ProcessWithMostThreads : Process [tomcat] has Thread Count [444]
    AppID : Cisco RIS Data Collector
    ClusterID : StandAloneCluster
    NodeID : CALIDCUCVM01
    TimeStamp : Tue Jan 21 14:46:07 EST 2014
    If anyone has encountered this issue or has any troubleshooting steps please let me know.
    Thansk,
    AK

    AK,
    Go to Cisco Unity Connection Administration page> System Settings, Service Parameters, Server, Service -> Cisco Ris Data Collector, Maximum Number of Processes and Threads. Check the value you might want to configure the Service Parameter Maximum Number of Processes and Threads to '2500' value
    Regards,
    davidsecretchord

  • Ask the Expert: Overview of Cisco Prime Service Catalog and Process Orchestrator Solutions

    Welcome to this Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about the Cisco Prime Service Catalog and Process Orchestrator solutions.
    Cisco expert Jason Davis will discuss Cisco’s network management products offered under the Cisco Prime framework. If you have questions about Cisco Prime infrastructure or data center automation with our Cisco Prime Service Catalog and Process Orchestrator solutions, join us on the Cisco Support Community.
    Jason Davis is a distinguished services engineer in the Intelligent Infrastructure Practice team of Cisco Advanced Services. His role is to provide strategic and tactical consulting for hundreds of Advanced Services customers, lead service innovation, and assess new services and technologies. Jason's primary expertise areas are in network management systems, intelligent automation, virtualization, data center operations, software-defined networking, and network programmability.
    Based out of the Research Triangle Park (RTP) campus, Jason is also responsible for administering the Research Triangle Park Network Management Lab, Cisco's largest network management lab.
    Since joining Cisco in 1998, Jason has been a frequent speaker at Cisco's Networkers and CiscoLive conferences in the United States and Europe. In the past five years he has also been involved in the conference network setup and monitoring. He is a much sought-after resource by the field sales teams to assist with presales solutions and executive briefings. He has provided strategic and tactical network management consulting for several hundred customers.
    Jason is a subject matter expert with the following products and features:
    Cisco Prime LAN management solution
    Cisco Prime infrastructure
    CiscoSecure ACS
    Cisco Prime Network Registrar
    Cisco Process Orchestrator
    Cisco Prime Service Catalog
    Cisco IP SLA
    Embedded Event Manager
    SNMPv3
    onePK and OpenFlow
    Cisco UCS
    Device instrumentation
    VMware ESX, ESXi, and vCenter
    ITIL
    Jason received his bachelor of science degree in electrical engineering from the University of Miami (FL). He has been married for 20 years and has 4 children. His interests include providing audiovisual technical support for churches and conference venues, camping and biking with his family, remote-control helicopter piloting, paintball, and recreational shooting.
    Remember to use the rating system to let Jason know if you have received an adequate response.
    Because of the volume expected during this event, Jason might not be able to answer every question. Remember that you can continue the conversation in Data Center > Intelligent Automation under the subcommunity Cisco Prime Service Catalog shortly after the event. This event lasts through September 12, 2014. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

    Hello Jason,
    Thank you very much for welcoming me to your expert discussion :) I feel to be in the right place, at the right time. Thank you also for answering question beyond your scope here, much appreciated. The information received will help me to go further as such I have submitted a 5 start rating for your first reply.
    That sounds promising about the LMS part so yes, I stay tuned and wait patiently.
    Ok, now let’s revert to the actual topic discussed here. Cisco Prime Service Catalog and Process Orchestrator solutions I have briefly read up on this on CCO (where elseJ) and picked out the following quote
    ---- Quote from the Cisco Prime Service Catalog Data Sheet
     Today’s end users want self-service and easy access to IT tools and services.
    Simultaneously, organizations are seeking ways to extend their cloud management
    platforms beyond self-service delivery of virtual machines and infrastructure resources
    while increasing their use of cloud-based solutions to enhance business agility and effectiveness.
    Cisco Prime™ Service Catalog offers tremendous benefits to organizations that want to unify the ways in
    which all types of IT services are ordered and fulfilled, not just infrastructure requests
    ---- un quote ---
    I try to understand what (at high level of course) happens in the back ground when an order is raised and which vendor solution your product can interact with.
    As mentioned in the quoted text, this service catalogue goes beyond the standard infrastructure.
    Let’s say, a user wants to deploy a new email services, or in your example,  extends or create a new web-portal (i.e. for HR to view and manage holiday, staff absence and benefits).
    Your solution will need to interact somehow with the 3rd party vendor application that is capable building such portal I believe.
    Without disclosing to many information, I assume the portal is linked to backend VM,s that spin up requested resources (and more magic of course). Perhaps I am mixing this up with another cisco product where a user can go on the portal and spin up virtual Firewalls, virtual Routers can be provisioned in now time.
    Out if interest; Is this product also known as Mozart? (project code within Cisco?)
    I hope query is ok.
    Best wishes
    Markus

  • Tomcat service does not start on Win2003

    Friends,
    I installed Apache Tomcat on Win2003 (after changing the installer to XP compatible mode). The installation went through without any visible errors. But when i try to start the Tomcat server, but it throws an error message "The Apache Tomcat service on Local Computer started and then stopped. Some services stop automatically if they have no work to do, for example, the Performance Logs and Alerts service."
    I looked at the stderr.log file under the Tomcat/log folder. It says "java.lang.NoClassDefFoundError: org/apache/catalina/startup/Bootstrap
    Exception in thread "main"
    I am not having any problems in Win2K and XP. The installation works just fine.
    Any suggestions/feedback is appreciated.
    Thank you.
    Pat

    In the installation script you'll see that java.class.path has to be given to the service. There should be three JAR files:
    bootstrap.jar in the TOMCAT_HOME/bin directory
    servlet-api.jar in the TOMCAT_HOME/common/lib directory
    tools.jar in the JAVA_HOME/lib directory.
    Sounds like the service installation missed bootstrap.jar. Uninstall the service, modify the script to pass a parameter like this to the JVM:
    -Djava.class.path=TOMCAT_HOME/bin/bootstrap.jar;TOMCAT_HOME/common/lib/servlet-api.jar;JAVA_HOME/lib/tools.jarJust one caveat: they switched from JavaService to the new Jakarta Daemon class for implementing the service when they went from Tomcat 4.1 to 5.0. Things might be a little different.

  • Ask the Expert: Integrating Cisco Identity Service Engine (ISE) 1.2 for BYOD

    With Eric Yu and Todd Pula 
    Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions  about integrating Cisco ISE 1.2 for BYOD with experts Eric Yu and Todd Pula.
    Cisco Bring Your Own Device (BYOD) is an end-to-end architecture that orchestrates the integration of Cisco's mobile and security architectures to various third-party components. The session takes a deep dive into the available tools and methodologies for troubleshooting the Cisco BYOD solution to identify root causes for problems that stem from mobile device manager integration, Microsoft Active Directory and certificate authority services, and Cisco Enterprise Mobility integration to the Cisco Identity Services Engine (ISE). 
    Todd and Eric recently delivered a technical workshop that helps network designers and network engineers understand integration of the various Cisco BYOD components by taking a deep dive to analyze best practice configurations and time-saving troubleshooting methodologies. The content consisted of common troubleshooting scenarios in which TAC engineers help customers address operational challenges as seen in real Cisco BYOD deployments.
    Eric Yu is a technical leader at Cisco responsible for supporting our leading-edge borderless network solutions. He has 10 years of experience in the telecommunications industry designing data and voice networks. Previous to his current role, he worked as a network consulting engineer for Cisco Advance Services, responsible for designing and implementing Cisco Unified Communications for Fortune 500 enterprises. Before joining Cisco, he worked at Verizon Business as an integration engineer responsible for developing a managed services solution for Cisco Unified Communications. Eric holds CCIE certification in routing and switching no. 14590 and has two patents pending related to Cisco's medianet.   
    Todd Pula is a member of the TAC Security and NMS Technical Leadership team supporting the ISE and intrusion prevention system (IPS) product lines. Todd has 15 years of experience in the networking and information security industries, with 6 years of experience working in Cisco's TAC organization. Previous to his current role, Todd was a TAC team lead providing focused technical support on Cisco's wide array of VPN products. Before joining Cisco, he worked at Stanley Black & Decker as a network engineer responsible for the design, configuration, and support of an expansive global network infrastructure. Todd holds his CCIE in routing and switching no. 19383 and an MS degree in IT from Capella University.
    Remember to use the rating system to let Eric and Todd know if you have received an adequate response.
    Because of the volume expected during this event, Eric and Todd might not be able to answer every question. Remember that you can continue the conversation in the Security community, subcommunity AAA, Identity and NAC, shortly after the event. This event lasts through November 15, 2013. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

    Hi Antonio,
    Many great questions to start this series.  For the situation that you are observing with your FlexConnect configuration, is the problem 100% reproducible or is it intermittent?  Does the problem happen for one WLAN but not another?  As it stands today, the CoA-Ack needs to be initiated by the management interface.  This limitation is documented in bug CSCuj42870.  I have provided a link for your reference below.  If the problem happens 100% of the time, the two configuration areas that I would check first include:
    On the WLC, navigate to Security > RADIUS > Authentication.  Click on the server index number for the associated ISE node.  On the edit screen, verify that the Support for RFC 3576 option is enabled.
    On the WLC, navigate to the WLANs tab and click on the WLAN ID for the WLAN in question.  On the edit screen, navigate to Security > AAA and make sure the Radius Server Overwrite interface is unchecked.  When this option is checked, the WLC will attemp to send client authentication requests and the CoA-Ack/Nak via the dynamic interface assigned to the WLAN vs. the management interface.  Because of the below referenced bug, all RADIUS packets except the CoA-Ack/Nak will actually be transmitted via the dynamic interface.  As a general rule of thumb, if using the Radius NAC option on a WLAN, you should not configure the Radius Server Overwrite interface feature.
    Bug Info:  https://tools.cisco.com/bugsearch/bug/CSCuj42870
    For your second question, you raise a very valid point which I am going to turn into a documentation enhancement request.  We don't currently have a document that lists the possible supplicant provisioning wizard errors that may be encountered.  Please feel free to post specific errors that you have questions about in this chat and we will try to get you answers.  For most Android devices, the wizard log file can be found at /sdcards/downloads/spw.log.
    As for product roadmap questions, we won't be able to discuss this here due to NDA.  Both are popular asks from the field so it will be interesting to see what the product marketing team comes up with for the next iterration of ISE.
    Related Info:
    Wireless BYOD for FlexConnect Deployment Guide

  • Cisco Identity Services Engine (ISE) Version 1.2: What's New in Features and Troubleshooting Options

    With Ali Mohammed
    Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about what’s new in Cisco Identity Services Engine (ISE) Version 1.2 and to understand the new features and enhanced troubleshooting options with Cisco expert Ali Mohammed.
    Cisco ISE can be deployed as an appliance or virtual machine to enforce security policy on all devices that attempt to gain access to network infrastructure. ISE 1.2 provides feature enrichment in terms of mobile device management, BYOD enhancements, and so on. It also performs noise suppression in log collection so customers have greater ability to store and analyze logs for a longer period.
    Ali Mohammed is an escalation engineer with the Security Access and Mobility Product Group (SAMPG), providing support to all Cisco NAC and Cisco ISE installed base. Ali works on complicated recreations of customer issues and helps customers in resolving configuration, deployment, setup, and integration issues involving Cisco NAC and Cisco ISE products. Ali works on enhancing tools available in ISE/NAC that are required to help troubleshoot the product setup in customer environments. Ali has six and a half years of experience at Cisco and is CCIE certified in security (number 24130).
    Remember to use the rating system to let Ali know if you have received an adequate response.
    Because of the volume expected during this event, Ali might not be able to answer each question. Remember that you can continue the conversation on the Security community, sub-community shortly after the event. This event lasts through September 6, 2013. Visit this forum often to view responses to your questions and the questions of other community members.

    Hi Ali,
    We currently have a two-node deployment running 1.1.3.124, as depicted in diagram:
    http://www.cisco.com/en/US/docs/security/ise/1.2/upgrade_guide/b_ise_upgrade_guide_chapter_010.html#ID89
    Question 1:
    After step 1 is done, node B becomes the new primary node.
    What's the license impact at that stage, when the license is mainly tied to node A, the previous primary PAN?
    Step 3 says to obtain a new license that's tied to both node A & node B, as if it's implying an issue would arise, if we leave node B as the primary PAN, instead of reverting back to node A.
    =========
    Question 2:
    When step 1 is completed, node B runs 1.2, while node A runs 1.1.3.124.
    Do both nodes still function as PSN nodes, and can service end users at that point? (before we proceed to step 2)
    Both nodes are behind our ACE load balancer, and I'm trying to confirm the behavior during the upgrade, to determine when to take each node out of the load balancing serverfarm, to keep the service up and avoid an outage.
    ===========
    Question 3:
    According to the upgrade guide, we're supposed to perform a config backup from PAN & MnT nodes.
    Is the config backup used only when we need to rollback from 1.2 to 1.1.3, or can it be used to restore config on 1.2?
    It also says to record customizations & alert settings because after  the upgrade to 1.2, these settings would change, and we would need to  re-configure them.
    Is this correct? That's a lot of screen shots we'll need to take; is there any way to avoid this?
    It says: "
    Disable services such as Guest, Profiler, Device Onboarding, and so on before upgrade and enable them after upgrade. Otherwise, you must add the guest users who are lost, and devices must be profiled and onboarded again."
    Exactly how do you disable services? Disable all the authorization policies?
    http://www.cisco.com/en/US/docs/security/ise/1.2/upgrade_guide/b_ise_upgrade_guide_chapter_01.html#reference_4EFE5E15B9854A648C9EF18D492B9105
    ==================
    Question 4:
    The 1.1 user guide says the maximum number of nodes in a node group was 4.
    The 1.2 guide now says the maximum is 10.
    Is there a hard limit on how many nodes can be in a node group?
    We currently don't use node group, due to the lack of multicast support on the ACE-20.
    Is it a big deal not to have one?
    http://www.cisco.com/en/US/customer/docs/security/ise/1.2/user_guide/ise_dis_deploy.html#wp1230118
    thanks,
    Kevin

  • Database Connection stops Tomcat service

    Hi,
    I have a servlet runnning on tomcat 5.5. I am able to query the database and return results in a new page. AT this point if I hit the back button or type in the link for the original index.html page and resubmit my query, Tomcat service stops and I get an error message.
    Can anyone help
    ackage cpecode;
    import java.io.*;
    import javax.servlet.*;
    import javax.servlet.http.*;
    import java.util.*;
    import java.sql.*;
    import java.lang.*;
    import java.text.*;
    public class cpeLogin extends HttpServlet {
    private Statement st = null;
    private Statement st2=null;
    private Connection c = null;
    private String URL = "jdbc:odbc:cpeSQL";
    //private String URL="jdbc:sqlserver://localhost:1433;"+"databaseName=cpeSQL;user=sa;password=administration10;";
    private String query,query2;
    private ResultSet rs=null;
    private ResultSet rs2=null;
    private HttpServletRequest req;
    private HttpServletResponse res;
    private PrintWriter output;
    private String ss,dob,lname,fname,keyfields,email,phone;
    private Locale currentLocale=new Locale("en","US");
    private SimpleDateFormat formatter=new SimpleDateFormat("MM/dd/yy",currentLocale);
    private SimpleDateFormat formattert=new SimpleDateFormat("hh:mm",currentLocale);
    private String apdate, compdate, dateofaction, action, course, comment;
    private int keyfield,seatint;
    private String wdate,wtime,room,seats,radioout;
    public void init(ServletConfig config) throws ServletException{
    super.init(config);
    try {
    Class.forName( "sun.jdbc.odbc.JdbcOdbcDriver" );
    //Class.forName("com.microsoft.sqlserver.jdbc.SQLServerDriver");
    c =
    DriverManager.getConnection( URL, "sa", "administration10" );
    //DriverManager.getConnection(URL);
    catch ( Exception e ) {
    e.printStackTrace();
    c = null;
    return;
    public void doGet( HttpServletRequest req,
    HttpServletResponse res )
    throws ServletException, IOException{
    this.req=req;
    this.res=res;
    ss = req.getParameter( "ss" );//field is named this in database
    dob=req.getParameter("dob");
    lname=req.getParameter("from");
    email=req.getParameter("email");
    phone=req.getParameter("telnr");
    output = res.getWriter();
    res.setContentType( "text/html" );
    //output.println("<h1>test</h1>");
    //check that id is valid
    try{
    st=c.createStatement();
    query="Select * from simb103 where sslastfour='" + ss + "' and dob='" dob"'";
    rs=st.executeQuery(query);
    boolean moreRecords = rs.next();
    // If id does not exist, display a message
    if ( ! moreRecords ) {
    output.println("<FONT COLOR='#000000'><H1><U>CPE REGISTRATION</U></H1><HR>");
    output.println( "<H3> Invalid DOB or SS. Press Back Button and try again.</H3></FONT>" );
    output.close();
    st.close();
    c.close();
    return;
    lname=rs.getString("lastname");
    fname=rs.getString("fname");
    //for testing connection
    if (moreRecords) {
         output.println("<HTML>");
                        output.println("<HEAD>");
                        output.println("<FONT COLOR='#000000'><TITLE><CENTER>CPE REGISTRATION<HR></TITLE></HEAD><BODY>");
                        output.println("<H1><CENTER>YORK COLLEGE CPE REGISTRATION</H1></CENTER>");
    output.println(ss);
    output.println("<p></p>");
    output.println(query);
    output.println(rs.toString());
    output.println(lname);
    output.println(rs.getString("dob"));
    output.println("</font></html>");
    output.close();
    st.close();
    c.close();
    return;
    public void destroy(){
    try {
    if (c !=null){
    c.close();
    catch( Exception e ) {
    System.err.println( "Problem closing the database" );
    index.html
    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
    <!-- saved from url=(0014)about:internet -->
    <HTML lang="EN">
    <HEAD>
    <TITLE>YORK COLLEGE CPE REGISTRATION</TITLE>
    <META http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
    <META NAME="description" CONTENT="">
    <META NAME="keywords" CONTENT="">
    <LINK href='../basic.css' rel='stylesheet'>
    <LINK rel="shortcut icon" href="../img/siteicon.ico" type="image/x-icon">
    <LINK REL=Contents HREF="index.html">
    <LINK REL=Home HREF="../index.html">
    <LINK REL=Search HREF="../search.htm">
    <LINK REL=Author HREF="contact.html">
    <SCRIPT TYPE="text/javascript" src=cpeval.js>
    </SCRIPT>
    <STYLE TYPE="text/css">
    @import url(../extrastyles.css);
    @import url(formval.css);
         .runinhdr { font-weight: bold; font-size: 50%; padding-right: 1em; }
    </STYLE>
    </HEAD>
    <BODY>
    <DIV ID="page">
    <DIV ID="wmbanner">
    <H1>YORK COLLEGE CPE REGISTRATION</H1>
    </DIV>
    <SCRIPT TYPE="text/javascript">
    // Only script specific to this form goes here.
    // General-purpose routines are in a separate file.
    function validateOnSubmit() {
    var elem;
    var errs=0;
    // execute all element validations in reverse order, so focus gets
    // set to the first one in error.
    if (!validateTelnr (document.forms.demo.telnr, 'inf_telnr', true)) errs += 1;
    if (!validateEmail (document.forms.demo.email, 'inf_email')) errs += 1;
    if (!validatePresent(document.forms.demo.from, 'inf_from')) errs += 1;
    if (!validatess (document.forms.demo.ss, 'inf_ss', true)) errs += 1;
    if (!validatedob (document.forms.demo.dob,'inf_dob', true)) errs += 1;
    if (errs>1) alert('There are fields which need correction before sending');
    if (errs==1) alert('There is a field which needs correction before sending');
    return (errs==0);
    </SCRIPT>
    <FORM NAME=demo onsubmit="return validateOnSubmit()" METHOD=GET ACTION="cpeLogin">
    <TABLE CLASS=formtab SUMMARY="CPE REGISTRATION FORM">
    <TR>
    <TR>
    <TD><LABEL FOR=ss>Enter Last Four Digits of SS#:</LABEL></TD>
    <TD><INPUT TYPE=text NAME="ss" ID="ss" SIZE="35" MAXLENGTH="4"
    ONCHANGE="validatess(this, 'inf_ss', true);"></TD>
    <TD id="inf_ss">Required. </TD>
    </TR>
    <TR>
    <TD><LABEL FOR=dob>Enter your Date of Birth (yyyymmdd): </LABEL></TD>
    <TD><INPUT TYPE=text NAME="dob" ID="dob" SIZE="35" MAXLENGTH="8"
    ONCHANGE="validatedob(this, 'inf_dob', true);"></TD>
    <TD id="inf_dob">Required.</TD>
    </TR>
    <TD STYLE="width: 10em">
    <LABEL FOR=from>Your name:</LABEL></TD>
    <TD><INPUT TYPE=text NAME="from" ID="from" SIZE="35" MAXLENGTH="50"
    ONCHANGE="validatePresent(this, 'inf_from');"></TD>
    <TD id="inf_from"></TD>
    </TR>
    <TR>
    <TD><LABEL FOR=email>Your e-mail address:</LABEL></TD>
    <TD><INPUT TYPE=text NAME="email" ID="email" SIZE="35" MAXLENGTH="50"
    ONCHANGE="validateEmail(this, 'inf_email');"></TD>
    <TD id="inf_email"> </TD>
    </TR>
    <!-- Note: the element to receive error messages must contain some data (for most,
    if not all, browsers). A   is sufficent. -->
    <TR>
    <TD><LABEL FOR=telnr>Your telephone number:</LABEL></TD>
    <TD><INPUT TYPE=text NAME="telnr" ID="telnr" SIZE="35" MAXLENGTH="25"
    ONCHANGE="validateTelnr(this, 'inf_telnr', true);"></TD>
    <TD id="inf_telnr">Required. 10 digits only.</TD>
    </TR>
    <TR>
    <TD> </TD>
    <TD><INPUT TYPE="Submit" NAME="Submit" VALUE="Send"></TD>
    <TD> </TD>
    </TR>
    </TABLE>
    </FORM>
    <HR> <!-- ====================================== -->
    </BODY>
    </HTML>
    Kaminie

    Hi srini
    My intention is try to install oracle soa suite 11g ,for that my prerequisites are ,installing a database (for that i installed oracle 11g r2 instead of oracle 10g database ),installation was successful,
    after that i installed weblogic server 1033(weblogic server 11g)
    when i am trying to install rcu script ,its giving invalid service name ,i guess the script is meant for creating tables in the database ,i am following the below document for installing Rcu script
    http://blogs.oracle.com/SOA/2009/08/installing_oracle_soa_suite_11.html
    here in this above document it says that install the XE database, but for installing oracle soa suite 11g installing 10g database is not recommended, that the reason why I installed oracle win32_11gr2_database ,can please suggest me the solution for installing the rcu scriprt on oracle 11g database
    OS I am using:windows xp servicepack 2
    Serice name I used:XE
    Port:1521
    Thanks
    Dileep.k

  • The SQL Server Reporting Services (MSSQLSERVER) service hung on starting.

    Hi experts,
    The SQL Server Reporting Services (MSSQLSERVER) service hung on starting.
    we are receving these errors  twice per week.
     colud you share solution.

    Hi vijay_1234,
    When you try to start SSRS, are you receive a time-out error or other errors?
    To work around this problem, we can configure the computer so that the network does not retrieve trusted and untrusted CTLs. Please use one of the following methods:
    Change the Group Policy settings.
    Modify the registry.
    Increase the default service time-out.
    For more details, please refer to the following KB:
    http://support.microsoft.com/kb/2745448
    If the issue is still existed, please check RS Logs in the C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\LogFiles.
    Hope this helps.
    Thanks,
    Katherine Xiong
    Katherine Xiong
    TechNet Community Support

  • Error message when run the Cisco CRS Serviceability Utility on UCCX 4.5 server

    Hi,
       Everytime i run the Cisco CRS Serviceability Utility from the UCCX server, this message always appear "Error reading System Parameters" before the interface appear.
       After that, when i click the "System Parameters" tab and there were no any information displayed.
      So, i would like to know if there were any way could fix this problem.
      Thanks for any suggestion.
    B.rgds,
    Tong

    Tong,
    The description that you are ginving us sounds preaty much like this bug : CSCsi25913
    This is the link with the informatio:
    http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?caller=pluginredirector&method=fetchBugDetails&bugId=CSCsi25913
    HTH
    Please rate this post if was helpful
    Walter Solano
    CCNA Voice
    Cisco UCCX Specialist

  • Request for any Best Practice document for configuring Service Parameters on CUCM 9.1.1

    Hi Team,
    Could you please send if you have any  Best Practice document for configuring Service Parameters on CUCM 9.1.1. That would really help.
    Thanks,
    Guru

    Hi
    There's no 'best practice' as such, but there are a few that I think should be default:
    Enabling CDR, On-Hook Pickup, CFwdAll Override... but really the settings are specific to the requirements of the deployment.
    Aaron

Maybe you are looking for

  • There should be away to save all the url's one has in tabs in a specific window. Is there a way I can have them in a list without copying every address??

    I've run into this problem while researching certain topics. When all the sources are found for research, and I need to note all the sources of information, it'd be great to be able to list all the URL's I have open in the given window. Thanks for li

  • Installing own kernel...

    I have no problem git cloning my kernel of choice and configuring. My question is when compiling a new video drivers or any other package that might be dependent on Linux sources. I usually use the /usr/src directory. I am having trouble with the PKG

  • Mixed signal graph refresh

    im having some problems with refreshing my mixed signal graph.  This was my first try to get this to work. It basicly does what i want after i intitialize the values in the array and press the run button. Ever time after it seems the initial values o

  • Installing CC, uninstall CS6?

    Just installed my first CC app (Dreamweaver), went well.  I am a CS6 Design Premium convert.  Compliments to the designers, launched Dreamweaver CC and all my sites were there, no need to re-enter all the info.  I have a question, may be a simple one

  • Jars For Java Proxy

    Hi all I am creating a Java Proxy application. While importing the proxy zip created to my NWDS project I am getting the error due to missing jar files. Can anyone tell me which all jars have to be added and which all jar files are required. Regards