How to trace policy for native FTP

Hi guys,
I am trying to troubleshoot policy for native FTP (proxy port 8021 where FTP proxy is listening). The main reasons are wrong probably policy: we have usersA that are able to log into ftp via FTP proxy, but another usersB (another subnet) are not able to do the same (receiving "530 Login denied").
Questions:
- is there any way how can I troubleshoot/trace policy for native FTP?
- where/what access rules are applied to request placed to FTP proxy from users? I can see that there is option to disable "Native FTP" within access policies ("Protocols and User Agents" column) but all those checkboxes within all access policies rules are unchecked.
thanks for any help
michal

Hi Michal,
Yes you can trouble shoot the FTP connection issues that you are having. Follow these steps below:
To grep the access logs for an entry, SSH into the WSA and run the following command from the CLI:
1. Grep
2. Enter the number of the log you wish to grep.
[]> 1
3. Enter the regular expression to grep.
[]> IP of the PC that the issue is being re produced on.
4. Do you want this search to be case insensitive? [Y]>
5. Do you want to search for non-matching lines? [N]>
6. Do you want to tail the logs? [N]> Yes
7. Do you want to paginate the output? [N]>
If you have any questions or concerns please feel free to email or call me.
Sincerely,
Erik Kaiser
WSA CSE
WSA Cisco Forums Moderator

Similar Messages

  • How to trace reason for failure to synchronize customer in OPM Financials

    Sirs,
    I created a customer in Order Management and process Synchronize Customer in OPM Financials. The result is "Failed"
    How to trace the reason for the reason to synchronize?

    Sirs,
    I created a customer in Order Management and process Synchronize Customer in OPM Financials. The result is "Failed"
    How to trace the reason for the failure to synchronize?
    thanks!

  • How to trace Logs for WebService connectivity - 3rd Party to ECC

    Hi Experts,
    Basically it's a simple scenario, the 3rd party will send a soap request with the information in it and wiill be sent to ECC and be written on a table.
    I'm wondering on how to trace logs on the soap request sent from 3rd party to an ECC environment. I used Altova XMLSpy and soapUI and  to create a soap request from wsdl created in SOAMANAGER. Both of the software returns a response. Do these both of these software really sends data (soap request) going to the binded address or it's just i simulation that wsdl created is valid.
    Cheers,
    R-jay

    Hello,
    These third party tools send web service requests to SAP system. You can trace Service invocation and download the request and response payloads using SOAMANAGER. In Logs and Trace tab,  edit the Trace configuration with suitable trace level and expiration time.
    Thanks,
    Venu

  • How to define JMX policy for the operation ALSBConfigurationMBean.getRefs

    Hello,
    I'm trying to configure the JMX policies of my Weblogic Server.
    I have followed the recommandations from the http://docs.oracle.com/cd/E13222_01/wls/docs100/ConsoleHelp/taskhelp/security/DefinePoliciesforMBeans.html link.
    I try to run the following code on a client side :
    ALSBConfigurationMBean lConfigMBean = (ALSBConfigurationMBean) lDomainMBean.findService(ALSBConfigurationMBean.NAME, ALSBConfigurationMBean.TYPE, null);
    lConfigMBean.getRefs-BusinessServiceQuery);
    I got the exception :
    Caused by: weblogic.management.NoAccessRuntimeException: Access not allowed for subject: principals=[], on Resource com.bea.wli.sb.management.configuration.DelegatedALSBConfigurationMBean Operation: invoke , Target: getRefs
         at weblogic.management.mbeanservers.internal.SecurityInterceptor.isAccessAllowedInvoke(SecurityInterceptor.java:1173)
         at weblogic.management.mbeanservers.internal.SecurityInterceptor.checkInvokeSecurity(SecurityInterceptor.java:813)
         at weblogic.management.mbeanservers.internal.SecurityInterceptor.invoke(SecurityInterceptor.java:443)
         at weblogic.management.jmx.mbeanserver.WLSMBeanServer.invoke(WLSMBeanServer.java:323)
         at weblogic.management.jmx.MBeanServerInvocationHandler.doInvoke(MBeanServerInvocationHandler.java:544)
         at weblogic.management.jmx.MBeanServerInvocationHandler.invoke(MBeanServerInvocationHandler.java:380)
         at $Proxy154.getRefs(Unknown Source)
         at com.csg.cs.services.tech.TECH_RegistryService_1_RegistryPortImpl.getServiceRef(TECH_RegistryService_1_RegistryPortImpl.java:224)
         at com.csg.cs.services.tech.TECH_RegistryService_1_RegistryPortImpl.lookup(TECH_RegistryService_1_RegistryPortImpl.java:117)
         ... 63 more
    And so I want to setup the JMX policy to give the rights to my client. But in the JMX Editor the ALSBConfigurationMBean doesn't exist, and I don't know which bean I have to set up.
    Anyone do know where I can find how to define policy for the Operation "getRefs" of the "ALSBConfigurationMBean" ?
    thanks and regards

    OEG provides several filters for encryption (XML, S/MIME and PGP). It's also possible to accept client certificates via 2-way SSL or route to a destination over 2-way SSL. For further information check out the OEG docs.

  • Configure Nexus 5548 for native FC

    hi
    does anyone have steps on how to configure n5k for native fc to a storage controller and then map that to an interface running fcoe to a fabric interconnect say 6200 ?
    appreciate any pointers

    I hope this helps. For integrating UCS in FC NPV mode, you need to enable NPIV on the N5k (feature NPIV)
    Fiber Channel (FC) Ports on Nexus 5000
    Cisco Nexus 5000 is a Cisco Data Center switch platform that supports conventional Ethernet, Storage Area Network (SAN) and Fiber Channel over Ethernet (FCoE). The switch platform has support for connection directly to native Fiber Channel (FC) SAN network with its FC ports. This is needed at least for now as most of customers' storages are still using FC or are behind FC network.
    This post will look at specifically on how to enable FC ports on Nexus 5500 (Nexus 5548UP and Nexus 5596UP) when we need to connect and integrate to FC network. In addition to that, we will look at some of the rules or restrictions that are worth to note based on the current hardware implementation when allocating ports on the switch for FC.
    Cisco Nexus 5548UP and Nexus 5596UP are Unified Fabric switches that have 32 and 48 Fixed SFP+ ports, respectively. This fixed or built-in ports are unified ports which means that each of the ports can be used for conventional Ethernet, FCoE or FC. Out of the box, all of the 32 or 48 ports are "Ethernet" port type. As the name implies, with this port type, the port are ready for us to be used as conventional Ethernet port or for FCoE. Remember that FCoE is basically transporting FC traffic over Ethernet, so we need "Ethernet" port type for FCoE.
    In that case, what if we need to use some of the built-in ports for FC?
    To use some of the ports as FC ports, we need to change the port type of the port(s) that we intent to use for FC connection. Here's an example of commands to change port type on the switch:
    N5K(config)#slot 1
    N5K(config-port)#port 41-48 type fc
    N5K(config-port)#copy running-config startup-config
    N5K(config-port)#Reload
    As the above command example, we change ports 31 and 32 from the default "Ethernet" to "FC" type. Similarly, to convert back from FC to Ethernet port type:
    N5K(config)#slot 1
    N5K(config-port)#port 41-48 type ethernet
    N5K(config-port)#copy running-config startup-config
    N5K(config-port)#Reload
    Note: Refer to this Cisco's Command Reference document for further detail of this command: http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/command/reference/layer2/n5k-l2_cmds_p.html#wp2326019
    You might surprise that there's a reload command in the end? Yes, you need to reload the entire switch to convert  port type. So...one of the important notes here is that, as much as possible, convert the ports before the switch is in production.
    After the port type has been changed from Ethernet to FC, the FC port will not be enabled on the switch until FCOE feature is enabled:
    N5K(config)#feature FCOE
    C license checked out successfully
    fc_plugin extracted successfully
    FC plugin loaded successfully
    FCoE manager enabled successfully
    FC enabled on all modules successfully
    Enabled FCoE QoS policies successfully
    After that, we verify that the port type is changed successfully and the FC ports appear on the switch:
    N5K# show interface brief
    Interface  Vsan   Admin  Admin   Status          SFP    Oper  Oper   Port
                      Mode   Trunk                          Mode  Speed  Channel
                             Mode                                 (Gbps)
    fc1/41     1      auto   on      sfpAbsent        --     --           --
    fc1/42     1      auto   on      sfpAbsent        --     --           --
    fc1/43     1      auto   on      sfpAbsent        --     --           --
    fc1/44     1      auto   on      sfpAbsent        --     --           --
    fc1/45     1      auto   on      sfpAbsent        --     --           --
    fc1/46     1      auto   on      sfpAbsent        --     --           --
    fc1/47     1      auto   on      sfpAbsent        --     --           --
    fc1/48     1      auto   on      sfpAbsent        --     --           --
    Ethernet      VLAN    Type Mode   Status  Reason                   Speed     Port
    Interface                                                                    Ch #
    Eth1/1        1       eth  trunk  down    SFP validation failed       10G(D) 22
    Eth1/2        1       eth  access down    SFP not inserted            10G(D) --
    Eth1/3        1       eth  trunk  down    SFP validation failed       10G(D) 32
    Eth1/4        1       eth  access down    SFP not inserted            10G(D) --
    Besides the fixed ports, each of the switch model have slot for expansion module for increasing the port density. The number of slot is 1 for Nexus 5548UP and 3 for 5596UP. For supporting FC, the following modules are available to choose from:
    - Fibre Channel plus Ethernet module that provides eight Ethernet port and eight native Fibre Channel ports.
       The first 8 ports of this module is Ethernet port and the remaining 8 ports are FC ports. The location of  Ethernet and FC ports are indicated with different colors.
    http://3.bp.blogspot.com/-46A5Xu-iy3g/UALOGhdiW-I/AAAAAAAAAF4/DuhCP59VX54/s1600/Nexus+5000+-+Module2.PNG
    - Unified port module that provides up to sixteen Ethernet ports OR up to sixteen native Fibre Channel ports
       This is unified port, similar to the fixed or built-in ports whereby it's up to us to use the ports either for  Ethernet or FC. Probably you only want to use some of the ports or even the entire module for FC.
    http://4.bp.blogspot.com/-f95sJ9tsntM/UALOPrUXNpI/AAAAAAAAAGA/M4VA-C2Yh3U/s1600/Nexus+5000+-+Module3.PNG

  • How to create a group policy for a group not to logout from rdp

    there is already a global policy for all users in OU which will disconnect a rdp session after 15 min of inactivity and log user out in another 15 min, (logout 30minutes)
    how do I create another policy  for a group in that OU so that group user will not be logged out ( executives are asking for this)?

    Hi,
    In addition to Martin’s suggestions, we can also choose to change the scope of the existing GPO with Security Filtering.
    Regarding Security Filtering, the following article can be referred to for more information.
    Security filtering using GPMC
    http://technet.microsoft.com/en-us/library/cc781988(v=WS.10).aspx
    Filter Using Security Groups
    http://technet.microsoft.com/en-us/library/cc752992.aspx
    Best regards,
    Frank Shen

  • How do I set the delivery policy for a queue in iMQ 2.0?

    The list on page 67 of the 2.0 administration guide appears to be
    incomplete. Specifically, I'm interested in knowing how to set
    the default delivery policy for a Queue through the jmqobjmgr command.
    I need the valid attribute name to pass in to jmqobjmgr.

    The "queueDeliveryPolicy" is an attribute of a queue
    created in the broker - not in the administered object
    destination so that is why you are not seeing that
    attribute on the list on page 67.
    By default, the broker by will use the "single" queue delivery
    policy unless you choose to change the values of the property
    "jmq.queue.defaultdeliveryPolicy" to SINGLE, ROUND-ROBIN, or
    FAILOVER. If you would like to do this, see the Chapter 4
    in the admin guide on "Starting and Configuring the Broker".
    It may be easier to set the delivery policy for just one queue.
    To do this, you can use the following command:
    jmqcmd create dst -n myQueue -t q -o "queueDeliveryPolicy=f"
    where valid values to queueDeliveryPolicy is f, s, r.
    You can do a 'jmqcmd -H' to get more info on queue attributes or
    see Chapter 6 in the admin guide on "Creating and Destroying Destinations".

  • How to change an OD policy for existing accounts

    OS X server 10.4
    I set up Open Directory with one of the policies being specification to reset password upon first login.
    I then imported a batch of accounts from a unix /etc/passwd file with the standard settings header.
    I changed my mind about the reset password policy and made the change in Server Admin.
    I also am changing password type from crypt to open directory in the Work Group Manager (WGM) for each user. Upon each change, a new password is prompted for and set.
    I now find that accounts created via the import process and had password type changed in WGM, along witha a new password setting, cannot get authorization services, for example ssh login or mail, unless the user logs in at an OS X login screen where they are prompted for a new password as required by the policy when their account was created but after the policy is changed in Server Admin.
    1. Are OD Server Admin policy changes only applied to accounts made after a policy change save?
    2. How do I change the OD policy for a single account, or perhaps a collection of accounts?
    -Thanks

    Policies can be set for all users at a site in Server Admin, or they can be set for users in Workgroup Manager. In WGM, the options are in the Advanced tab. Policies set on a specific user generally override those set in Server Admin. When policies are set, they become active for all existing and new users. The option, "password must be reset on first user login" is the exception. It dictates how accounts are created. Once an account is flagged for a password change, it must be unset in WGM. Go to the Advanced tab for the user and click the Options button.

  • How to set password policy for apps users

    Hi All,
    Can anyone please help me.
    I am working on apps 11i.
    How to set password policy for users
    Thanks

    Check Note: 189367.1 - Best Practices for Securing the E-Business Suite
    https://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=189367.1

  • How to implement password policy for a software in oracle (sql) forms & reports 6i ?

    Hi all , I have to implement password policy for an already existing software which was created 2 to 3 years before.
    What exactly i want to do is I must alert the user every month to change his/her password. I have no idea about it.
    Can anyone help me how to start with it? Or can you provide me the links where i can learn & implement in the software?
    Oracle Forms & Reports Builder 6i.
    Oracle9i Enterprise Edition Release 9.2.0.1.0 - Production.
    Thank You.

    You can try this:
    Establishing Security Policies
    Using database policy, you can force user to change password with Oracle forms 6i.
    Regards

  • How to enable SSL for policy service?

    Hi all,
    My application is using SunONE's C API to communicate with the Identity Server.
    In order to enable SSL, I have changed the following lines in amconfig.properties:
    com.sun.am.namingURL = https://id01.core.development.net:443/amserver/namingservice
    com.sun.am.policy.am.loginURL = https://id01.core.development.net:443/amserver/UI/Login
    com.sun.am.policy.am.library.loginURL = https://id01.core.development.net:443/amserver/UI/Login
    After operating these changes, everything continued to work fine...but then, I checked with a network sniffer what data is being sent to IS:
    - The login and naming data were over SSL
    - Policy and session items were plain HTTP
    My questions are:
    1. How to enable SSL for policy evaluation requests?
    2. How to enable SSL for sessionservice requests?
    3. What are the changes required on the server/client?
    Many thanks,
    Dan

    There might a better different forum for this question.

  • How to migrate certificate for a native installer

    Hello,
    We have a native AIR app that uses some native files, so it needs to be packaged using "adt -package -target native [files...]" command and cannot be created as an AIRI file.
    We include the SWF file, the app description XML and the required native files into the installer, and we also include our code signing certificate into this command line, and everything worked great.
    Recently our code signing certificate expired, and we released an update with a new certificate.
    However on the machines where our application had been installed previously, installation fails with the following error.
    The certificate of the installed app fails to match either the signature or migration signature of the AIR file
    It turns out that AIR framework expects a migration signature for applications that had been installed before and changed certificate.
    The problem is that "adt -migrate" command expects an .AIR file, and fails to migrate a native installer (such as .EXE or .APP).
    How should we migrate a native installer? is there any option in adt to do this?
    Thank you in advance,
    Anatoly

    I know this is an older post, but it helped me find out how to make the migration procedure for native installer. I tried it with self signed certificate created by ADT tool and everything went fine.
    But now, we obtained a commercial AIR signing certificate from Thawte and the process failes in step 3) ADT saying
    'Certificate in PATH_TO_P12 could not be used to sign setup.msi' on Windows.
    On mac, it says that signing native installer on OSX is not supported, so I skipped the signing option in step 3) and it worked fine.
    I can skip the signing option on Windows as well and the process succeeds, but running the installer on machines with previous versions of application results in "Installer mis-configured' error message - the same error as if the migration process was not applied.
    I already contacted Thawte if it is a certificate issue, reply from them was 'AIR certificate can only sign .air applications'. But when I build a native application directly from FlashBuilder and sign it with the Thawte certificate the whole process seem to succeed. The application can be installed on machines without previous version of the application. Those who already have the older version get the 'Installer mis-configured' error message.
    I want to mark out again, that the same process but with a self signed certificate created with ADT, is successfull and the application can be installer as an update on machines with older version of the app. So I assume the workflow is correct.
    Any ideas? Or somebody having the same issue?
    Thanks

  • How do i start an Oracle Trace?   For a currently running session?

    How do i start an Oracle Trace? For a currently running session? How do i read it?

    How do i read it? Ohh forgot this one. That tracing will create a tracefile in udump directory and you need to run tkprof to parse that trace file so that you can read it. To find the udump dir type "show parameter user_dump_dest" at sqlplus prompt and then run tkprof like (from OS prompt):
    tkprof file_name.trc file_name.txt sys=no
    Type only tkprof for more option of this tool.
    Daljit Singh

  • How to generate the trace files for remote db link session's?

    User are complaining, the db link queries are performing slowness..
    how to enable the sql trace session for db link's in remote database...
    Is there any way to enable sqltrace for the dblink session ?
    if not how to enable the sql trace for entire database level, rather than session based...

    An explain plan of the SQL being ran on the local database will review the SQL being passed to the remote db. You can then explain that SQL on the remote db.
    I have had to tune a few distribued queries so more than likely the explain plan alone will be enough to allow you to tune the query to improve performance. If not then you can go to the trouble of trying to set up dual traces.
    HTH -- Mark D Powell --

  • How to trace every dml statement for a schema/ database

    hi,
    how to trace every dml statement for a schema/ database
    PFile Entrie
    init.ora Parameter Example event='1401 trace name errorstack, level 12';
    tkprof orcl_ora_3632.trc b.txt
    after these two steps I am not able to see the sql statements in trace ...
    Please suggest.
    Thanks & Regards,

    Hi,
    Trace Event 1401 will create a trace file and dumps the information when ORA-01401 error occurs. This error occurs when "inserted value too large for column"
    You will see the trace file getting populated only when you encounter ORA-01401 error.
    Regards

Maybe you are looking for

  • How can we convert soap wrapped xml to simple xml?

    I am getting a soap wrapped xml as payload to JMS in JMS queue and need to convert that into a simple xml. Can anyone please suggest how this can be done? I am adding the xml as an attachment. <?xml version="1.0" encoding="UTF-8"?> <SOAP-ENV:Envelope

  • More RAM in Macbook

    Hello, I have a Macbook 2.16 GHz Intel Core 2 Duo (Mid 2007) with 1GB RAM memory (two 512MB) of 667MHz DDR2 SDRAM (PC2-5300). I want to upgrade this RAM memory to 2GB, and I wonder if it would work if I put 1 memory of 2GB instead of 2 memories of 1G

  • Messages in forms for stored procedures/functions

    Hi! i wand to send message or raised exception from the stored procedure/function to the oracle forms during processing . how can i do this Thanking U

  • Adobe LiveCycle Designer 8 Beginner

    I am very much new to adobe form design tools. Now my company wants me to develop an eForms system using Adobe LiveCycle Designer 8. The requirements are like this All pdf forms will be saved in the file server. Users can enter data directly into the

  • CSS Styles are lost

    Anyone seen this behavior? we have a single user whose laptop has started losing the styles (fonts, pictures, colors, etc.) when she opens the Agile PLM for Porcess web application. Its Win 7 and IE8. Its only the PLM app pages doing this. All other