CiscoWorks LMS3.2 device selectability in RME Config Management
Hello
All of a sudden we are unable to select individual devices in RME / Config Management, devices appear grayed out, we are able to select the whole device group and run the job but not individual devices. If we go to Device Center we can select individual devices and perform tasks.
We have tried restarting server (windows) and stopping and starting CW Daemon Manager, not sure what else to look at.
Thanks in advance.
carl bagge
Please try to break the integration with the following procedure:
CiscoWorks to local login mode (bring down ACS integration)
1. Stop the daemon manager using:
On Windows: net stop crmdmgtd
On Solaris: /etc/init.d/dmgtd stop
2. Execute the following script:
On Windows: NMSROOT/bin/perl ResetLoginModule.pl
On Solaris:/opt/CSCOpx/bin/ResetLoginModule.pl
3. Start the daemon manager using:
On Windows: net start crmdmgtd
On Solaris: /etc/init.d/dmgtd start.
Note: You must have appropriate privileges on the system
Windows = Administrator
Solaris = root
After this check if you are able to perform all the tasks without being integrated with ACS and then integrate again, but in CW Common Services>Server>Security>AAA Mode Setup, please do not check the Application Registration box.
Similar Messages
-
4507R-E and RME Config Change Report
Hello,
We have a new 4507R-E Switch which RME keeps reporting as "CONFIG_CHANGE" each evening. When you click to see the change, the only thing that has changes is the "ntp clock-period".
However, we have configured "ntp clock-period" as an exclude command in RME Config Managment.
Any idea's for anything else which could be causing this?Bump.....We're still having this issue......does anyone have any ideas....
-
Ciscoworks LMS 3.0.1 RME devices management
Hello everyone,
I work with CW LMS 3.0.1 with the following product versions installed:
Products Installed
Showing 1-8 of 8 records
Product Name
Version With Patch Level
Installed Date
1.
CiscoWorks Common Services
3.1.1
02 Mar 2010, 10:34:04 CET
2.
Campus Manager
5.0.2
02 Mar 2010, 10:34:05 CET
3.
CiscoView
6.1.7
02 Mar 2010, 10:34:10 CET
4.
CiscoWorks Assistant
1.0.1
02 Mar 2010, 10:34:10 CET
5.
Device Fault Manager
3.0.5
02 Mar 2010, 14:55:12 CET
6.
Internetwork Performance Monitor
4.0.1
02 Mar 2010, 10:34:14 CET
7.
LMS Portal
1.0.1
02 Mar 2010, 10:34:17 CET
8.
Resource Manager Essentials
4.1.1
02 Mar 2010, 10:34:18 CET
Many Thanks in advance,
LucaI verified that RME has a license to support 1500 devices while the devices discovered by RME are about 1600.
Many of these devices have now been eliminated from the Network (around 200) and I want to know if there is a way to automatically remove them from CW or if I must remove them manually step by step.In LMS 3.0.1, you must remove them manually. LMS 3.2 has a feature which can poll devices in DCR, then generate a report for those which are no longer reachable. That will then facilitate removing those devices.
-
RME 4.3.1 not showing devices in the device select menu
Windows Server 2008 Standard LMS 3.2 with RME 4.3.1
When I try to select devices to check/compare device configurations in the RME Archive Mgmt menu (RME -> Archive Mgmt -> Compare Configs) no device shows up for me to select. I know the configurations are being archived because when I use the Device Troubleshooting diagnostic tool it shows me the latest configuration fetched for a device
Since it doesn’t show me devices to select from, if I try to search for a device in the device selection, the query ends but nothing is displayed. If I select advance search I get an error window with the following message:
Problem with File /WEB-INF/screens/deviceselector/DeviceFilter.jsp!!!Exception in JSP: /WEB-INF/screens/deviceselector/DeviceFilter.jsp:77 74: if (classtype != null && classtype.length() > 0) 75: javaClassArray = devFilterUtil.getSubClasses(classtype, false); 76: else 77: javaClassArray = devFilterUtil.getClasses(); 78: 79: 80: String javaAttributeArray[][] = devFilterUtil.getAttributes(javaClassArray); Stacktrace
From other applications such as Ciscoview, Campus Manager, Common Services I can see all the devices configured on the system
This was working just a few weeks ago. There have been windows updates applied to this server lately, so I’m wondering if any of them is causing the errors.
Thanks for any information.
Jorge JilesThe EssentialsDM daemon is in a waiting to initialize state, which points to CSCte49301 as a potential cause.
Symptom:
The EssentialsDM daemon hangs in a Waiting to initialize state (as seen in the output of the pdshow command). Additionally, one might see "Error connecting to JRM" in Resource Manager Essentials applications.
Conditions:
This occurs on Windows servers after the patch for KB968930 is installed, and only if the Windows Remote Management service was started prior to starting CiscoWorks Daemon Manager.
Workaround:
Shutdown CiscoWorks Daemon Manager with the following command from the server's command prompt:
net stop crmdmgtd
Delete the following two files:
NMSROOT\MDC\tomcat\webapps\rme\WEB-INF\lib\ctmregistry
NMSROOT\MDC\tomcat\webapps\rme\WEB-INF\lib\ctmregistry.backup
Restart CiscoWorks Daemon Manager with the following command:
net start crmdmgtd
If that does not work, then the Windows Remote Management service must be stopped, and disabled. Then, CiscoWorks Daemon Manager must be restarted. -
I am about to update/standardize to secure the SNMP configuration for all devices in the network utilizing Ciscoworks.
There is likely to be variations amongst the devices. Therefore, I would like to generate one report for all the devices, capturing the SNMP configurations, is this possible?
I know how to complete the work afterwards but am struggling to produce a meaningful report that I can use to build my tasks from.
I am trying to achieve this using a particular 'role based' account via ACS, so it is possible that I don't have the permissions with this account at present which maybe why I'm not able to do it.
Thanks!Getting the SNMP trap community string is not trivial. The reason for this is that anything which shows the configuration will have this field starred out. You can get to the value, but not in a report-like fashion. You can, however, search the archived configs under RME > Config Mgmt > Archive Mgmt > Search Archive. Assuming you know the SNMP trap receiver IP, you could search on:
snmp-server host x.x.x.x old-string
That would show you all devices that still had the old community string.
If you need to force RME to get the new config data, you can simply schedule a Sync Archive job under RME > Config Mgmt > Archive Mgmt > Sync Archive. Of course, if you made the changes outside of LMS, you will need to manually update DCR with the new community string. -
Call manager and rme config archive report
Hi,
I know that rme does not support the call manager for config archive. It is clear.
The RME home page show config archive status for failed devices and there are some devices which are not supported by RME config archive.
I've set this devices to suspended state in RME but config archiv is trying with this devices also.
This is a financial costumer and the local Financial supervisory authority would like to see all devices config is saving successfully.
How can i exclude the call manager and similar devices from config archiv process and status reports?
Regards,Hi,
I would like to qoute from RME help.
Working With Suspended Devices
Suspended device state cannot participate in any RME application flows but all historical data pertaining to the device will continue to be maintained by RME.
Nevertheless the RME is trying to fetch the config from suspended devices!!!
What is the truth in this thing?
Regards, -
Morning All,
We are in the process of setting up our SCCM 2012 infrastructure and are experiencing issues with our device collection querys based on AD security groups.
I can see the security groups are being updated per adsgdis.log - i can see the computers that are members of the groups in AD are being recorded in the same log. Issue is when we build the device collection query - click the value button for the string,
only 2 of the 18 AD security groups are displayed. These are 2 AD groups we setup initially to test.
We have since added several additional yet they only appear to populate as user groups in config manager.
The same goes for additional OUs that we have created with AD.
When i click the value button only the initial 10 OUs that were created are populating in the list of applicable OUs.
We have the discovery methods Group Discovery & System Discovery enabled and set to search the parent OU recursively
I'm wondering if there might be an SQL issue with this as it initially worked but stopped...
Additionally we added an OU recently that now appears in in the Values options in the query but the ones added previously and additionally after are not showing up....
Any help is appreciated.
Thanks,
JeffGiven the adsgdis.log lists the new pc and the group it's assigned to it appears the AD group discovery is working.
Have the following excert from the adsgdis.log
INFO: Processing discovered group object with ADsPath = 'LDAP://************.****.COM/CN=Software - Microsoft Project Professional 2010 x64,OU=Software,OU=US-West,DC=*****,DC=com' SMS_AD_SECURITY_GROUP_DISCOVERY_AGENT 10/4/2012 7:08:13 AM 8180
(0x1FF4)
INFO: DDR was written for group '*****\Software - Microsoft Project Professional 2010 x64' - E:\Program Files\Microsoft Configuration Manager\inboxes\auth\ddm.box\userddrsonly\asg8ud94.DDR at 10/4/2012 7:8:12. SMS_AD_SECURITY_GROUP_DISCOVERY_AGENT 10/4/2012
7:08:13 AM 8180 (0x1FF4)
INFO: DDR was written for system 'THURMANWIN7VM' - E:\Program Files\Microsoft Configuration Manager\inboxes\auth\ddm.box\adhh8419.DDR at 10/4/2012 7:8:12. SMS_AD_SECURITY_GROUP_DISCOVERY_AGENT 10/4/2012 7:08:13 AM 8180 (0x1FF4)
Here you can see it processes the new members in the Software - Microsoft Project Professional 2010 x64 group and captures Thurmanwin7vm as a member.
I did find some log entries that reference permission issues with objects in the SQL database and have opened a case with MS to get that looked into. Hopefully that will be where the issue lies. -
Ciscoworks LMS3.2 Device Support
I have recently upgraded to Ciscoworks LMS3.2 and noticed some devices are still showing as device type "unknown". Is there an update available for LMS3.2 to support G2 Routers such as the 1900, 2900, and 3900 series? If so, how do I go about applying this device update? Thanks.
You can upgrade to the latest device packages from DOS like this:
PSUCli.bat -p cmf -d -dst c:\psu_download -all
Will download Common Services packages to C:\psu_download\cmf. Then install this way:
PSUCli.bat -p cmf -install -src c:\psu_download\cmf -all
I prefer doing these device package updates via CLI as this lets you actually follow what is happening. -
I have devices loaded but new devices keep getting this error "Authentication failed on device 3 times. Failed to detect SSH version running on the device. PRIMARY-STARTUP config Fetch Operation failed for TFTP" - which trying to get configurations. I am using LMS 3.0.1
I tried to TELNET on devices via Putty port 22 no good. Please help?
Name Version License Status Size CiscoWorks Common Services 3.1.1 Licensed Not applicable Campus Manager 5.0.3 Purchased 1500 CiscoView 6.1.7 Licensed Not applicable CiscoWorks Assistant 1.0.1 Licensed Not applicable Device Fault Manager 3.0.3 Purchased 1500 Internetwork Performance Monitor 4.0.1 Purchased 1500 Integration Utility 1.7.1 Licensed Not applicable LMS Portal 1.0.1 Licensed Not applicable Resource Manager Essentials 4.1.1 Purchased 1500Showing 1-1 of 1 records
Go to page:
of 1 pages
Device Name
SysObjectID
Model
Device Status
Inventory Status
Inventory Last Updated Time
Config Status
Config Last Updated Time
1.
R2020012_01
.1.3.6.1.4.1.9.1.576
Cisco 2811 Integrated Services Router
Normal
Success
Jan 13 2011 10:43:49 EST
Failed
Jan 13 2011 10:37:24 EST
Rows per page:
20 50 100 500
Go to page:
of 1 pages -
How device select tacacs-server
Hi Guys,
We have Existing tacacs configuration form our devices and pointed the 2 ACS server. the acs server are manage with other vendor which the acs server is located at their site. Now were planning to manage the acs server. We Installed a new acs server from our location, we have thousand of devices, if we migrate to the new server can we just add the 2 acs server from the device? are the new acs server will able to comunicate from the device? how does a device select which primary or secondary acs server? please advise.
Old config
aaa new-model
aaa authentication login vtymethod group tacacs+ local
aaa authorization config-commands
aaa authorization exec default group tacacs+ local if-authenticated
aaa authorization commands 0 default group tacacs+ local if-authenticated
aaa authorization commands 15 default group tacacs+ local if-authenticated
aaa accounting send stop-record authentication failure
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 0 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+
aaa accounting system default start-stop group tacacs+
ip tacacs source-interface Loopback0
tacacs-server host 10.x.x.x
tacacs-server host 10.x.x.x
New config
aaa new-model
aaa authentication login vtymethod group tacacs+ local
aaa authorization config-commands
aaa authorization exec default group tacacs+ local if-authenticated
aaa authorization commands 0 default group tacacs+ local if-authenticated
aaa authorization commands 15 default group tacacs+ local if-authenticated
aaa accounting send stop-record authentication failure
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 0 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+
aaa accounting system default start-stop group tacacs+
ip tacacs source-interface Loopback0
tacacs-server host 10.x.x.x
tacacs-server host 10.x.x.x
tacacs-server host 100.x.x.x <-- new
tacacs-server host 100.x.x.x <-- newHi,
in your way above the TACACS+ servers will be used in order.
You can group TACACS+ servers together and choose to use servers in that group only:
aaa group server tacacs+ Test
server 10.10.10.10
aaa authentication login vtymethod group Test local
under the vty lines config:
login authentication vtymethod
in the above example, only the server in the group Test; which is 10.10.10.10 will be used in authentication.
HTH,
Amjad
Rating useful replies is more useful than saying "Thank you" -
CiscoWorks Changing Default Line Input during Config push
If no line input is specified as in this example
line con 0
line vty 0 4
password cisco
line vty 5 15
password cisco
does CiscoWorks change the default line input while pushing a configuration to "transport input none"?Config Editor allows you to edit and download configuration files to devices using a GUI instead of the command line interface (CLI). Use Config Editor to edit individual device configurations within RME and then download them back to a device.
For more details please follow up on this link:
http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_resource_manager_essentials/4.2/user/guide/cfgedt.html#wp1055028 -
Ciscoworks lms3.1 -- netconfig job problems
Hi,
LMS 3.1,when i do a netconfig job for more than >5 devices, in the job tab the status is always showing as running. But when i do it for 2 or 3 devices as a batch it comes as successfull. Nevertheless the configurations are updated when more than 5 devices selected. We tried to reboot the server also. All the services are running in the common services>server>admin>processes tab.
Pls find enclosed the netconfigclient & jrm log files. We started the jobs around Tue Nov 17 07:00:03 hrsAre you using SSH to connect to your devices? If so, then you are most likely seeing a known bug where SSH sessions can lock up either deploying a config, or fetching a config. All of the known SSH bugs are fixed in LMS 3.2, but patches for RME 4.2 are available from TAC. The bugs are CSCsv95235, CSCsx24218, and CSCsw88378.
-
Config Management Server is repeatedly crashing
Running LMS4.1 - the Config management server process 'crashes' after approximately 5 seconds of starting. The server log is showing the following message:
Exception in thread "ActiveMQ Session Task" java.lang.NoClassDefFoundError: com/cisco/nm/xms/ogs/client/OGSServerProxy
at com.cisco.core.mice.cam.cmf.CMFDeviceCache.reloadDeviceGrp(CMFDeviceCache.java:159)
at com.cisco.core.mice.cam.OGSEventListener.onMessage(OGSEventListener.java:141)
at org.apache.activemq.ActiveMQMessageConsumer.dispatch(ActiveMQMessageConsumer.java:1021)
at org.apache.activemq.ActiveMQSessionExecutor.dispatch(ActiveMQSessionExecutor.java:122)
at org.apache.activemq.ActiveMQSessionExecutor.iterate(ActiveMQSessionExecutor.java:192)
at org.apache.activemq.thread.PooledTaskRunner.runTask(PooledTaskRunner.java:122)
at org.apache.activemq.thread.PooledTaskRunner$1.run(PooledTaskRunner.java:43)
at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:886)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:908)
at java.lang.Thread.run(Thread.java:662)
The DCMAService log is showing messages similar to below:
[ Mon Oct 10 11:55:29 CST 2011 ],INFO ,[main],com.cisco.nm.rmeng.dcma.configmanager.DeviceArchiveManager,deleteDevice,1659,Deleted Archive for device 531
[ Mon Oct 10 11:55:29 CST 2011 ],FATAL,[main],com.cisco.nm.rmeng.util.DCRWrapperAPIs,getDCRId,1333,Device ID: 466 NOT in RMEHi,
shutdown dmgtd
then remove ctmregistry* from NMSROOT/MDC/tomcat/webapps/rme/WEB-INF/lib.
Also disable the Anti-virus running on the server ,If applicable
Thenstart dmgtd
Now check the status of the issue. If you still find the same issue then send me the below information:
CTMJrmServer.log
jrm.log
JrmUser.properties and md.properties (CSCOpx/lib/classpath)
Output of pdshow
ctm_config.txt (CSCOpx\mdc\tomcat\shared\lib)
Is there any 3rd Party application been Installed on the server ?
Thanks
Afroj -
Config Manager 2012 R2 Update Failed - Now What?
Starting Environment:
Windows Server 2012 VM
Configuration Manager 2012 CU1
SQL Server 2012 Enterprise SP1 installed on a separate 2 node cluster
We have been running this setup for Config Manager 2012 CU1 for about a year now with no issues at all. In an effort to deploy Windows 8.1 I ran the Configuration Manager 2012 R2 Update. The update failed halfway through. From the ConfigMgrSetup.log
it looks like it wasn't able to connect to the database and this is why the update failed. Problem is after the install failed I am no longer able to connect to the database when opening the CM console. I get the "Configuration Manager cannot connect
to the site" message. Here is the error from the SMSAdminUI.log:
[02/24/2014 19:10:21] :Transport error; failed to connect, message: 'The SMS Provider reported an error.'\r\nMicrosoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlQueryException\r\nThe SMS Provider reported an error.\r\n at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlQueryResultsObject.<GetEnumerator>d__0.MoveNext()
at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlConnectionManager.Connect(String configMgrServerPath)
at Microsoft.ConfigurationManagement.AdminConsole.SmsSiteConnectionNode.GetConnectionManagerInstance(String connectionManagerInstance)\r\nConfigMgr Error Object:
instance of __ExtendedStatus
Operation = "ExecQuery";
ParameterInfo = "SELECT * FROM SMS_Site WHERE SiteCode = 'EPS'";
ProviderName = "WinMgmt";
Error Code:
ProviderLoadFailure
\r\nSystem.Management.ManagementException\r\nProvider load failure \r\n at System.Management.ManagementException.ThrowWithExtendedInfo(ManagementStatus errorCode)
at System.Management.ManagementObjectCollection.ManagementObjectEnumerator.MoveNext()
at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlQueryResultsObject.<GetEnumerator>d__0.MoveNext()\r\nManagementException details:
instance of __ExtendedStatus
Operation = "ExecQuery";
ParameterInfo = "SELECT * FROM SMS_Site WHERE SiteCode = 'EPS'";
ProviderName = "WinMgmt";
\r\n
[10, PID:6140][02/24/2014 19:10:21] :System.Management.ManagementException\r\nProvider load failure \r\n at System.Management.ManagementException.ThrowWithExtendedInfo(ManagementStatus errorCode)
at System.Management.ManagementObject.InvokeMethod(String methodName, ManagementBaseObject inParameters, InvokeMethodOptions options)
at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlConnectionManager.ExecuteMethod(String methodClass, String methodName, Dictionary`2 methodParameters, Boolean traceParameters)\r\nManagementException details:
I have tried running the R2 update again but am now faced with the following 2 failures during run check:
Current SUM configuration uses virtual locations for some of the active SUPs. Please remove any virtual locations from the existing SUM configuration.
There is an active source hierarchy configured for migration. Please stop data gathering for each source site in the source hierarchy.
I do not know how I can fix these errors without being able to connect through the console.
Does anyone have any ideas on how I can reconnect the console to the database and eventually successfully run the R2 update?
Database itself seems fine. No errors. Database mounts fine.
Thanks in advance for any input.Hi,
I saw a similar problem with yours. It should be helpful.
http://social.technet.microsoft.com/Forums/en-US/dda03cc4-e78e-409b-a9dd-f6d8a4f96774/upgrade-to-system-center-2012-sp1-prerequisite-check-failed-with-error-software-update-points-in?forum=configmgrsum
Best Regards,
Joyce Li
We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place. -
PCs not showing in Collection/Queries Config Manager 2012 R2 - Direct Rule
Hello,
I have been creating some collections and queries using a direct rule or manual entry of the device and the PC is not showing in the collection.
Example: Created collection for a .NET 4.5.2 install that I rolled out. Manually added the devices that need the application and of the 40 PCs 2 or 3 will not appear in the collection, thus they are not getting the software push. The PCs
that are not showing up are pinging able and I can RDP into them just fine. Config Manager shows they have the Client, are active and getting policy requests.
I thought maybe it there was an issue with the collection I was creating but I tried adding the same PCs to other collections and they do not appear in those collections either.
I did a manual query as well with the same results, the same PCs I try to add to the collections are not showing in my query even though they are hard coded in.
Thanks
RichI deleted the collection for our "Insurance Department" which the suspect PCs were in. I no longer needed the Insurance collection so I deleted that just to see if that was limiting the .NET collection. Now those PCs are showing in
the ".NET 4.5.2" collection.
That is good and everything but going forward I will need to have a collection for the "Insurance Department" that will be based on a query that looks for our Insurance Application in Installed Applications64. How can I prevent this new collection
from limiting any PC in that collection from being put into other Software Install collections?
Thanks for the help thus far.
Maybe you are looking for
-
HP Deskjet F4440 not printing from cups, do I need ppd? Where can I find it?
Hello!, I am trying to get my HP Deskjet F4440 connected to my linux server through the use of "cups". I am using Tiny Core Linux. Linux box 3.16.6-tinycore #777 SMP i686 GNU/Linux I have installed and configured cups.tcz. When I visit the cups admin
-
If I use AOL's browser, I can print Web pages. But not from Firefox. Could be this problem began with upgrade to your 4.0.1.
-
Row level Security in obiee11g
Hello I am trying to implement Row Level security for some 10,000 users based on the Cost Centers which are about 30,000. I know how to implement the data level security using groups an dapplication roles and creating security filters on those groups
-
Installing Grid Control and its agents in RAC
Hi I have a RAC of 2 nodes in 10.2.0.5 . I need to install Grid Control in another server to manage the RAC. I have several questions.... The agent and grid control to be install has to be in 10.2.0.5 as well ? or must be higher... I have to install
-
Purchased Elements 11 in October. Received serial number from Adobe. The Editor part will not accept the serial number . How can I get Editor to work?