Shutdown port with CiscoView - cisco prime LMS4.2

Buenos dias.
No puedo realizar ninguna actividad con los puertos a traves del cisco view. me sale un error.
Message
Cannot access the required SNMP object due to restricted SNMP view setting.
Ya configuré en el sw cisco la version snmp3.
Good morning.
I can not perform any activity through the ports cisco view. I get an error.
Message
Can not access the required SNMP object due to restricted SNMP view setting.
Since I configured the cisco sw version snmp3.

Your question as a double aspect and sides:
1. Can you retrict access to help-desk users from device side?
2. Can this be retricted from LMS point of view.
Answers:
Possible from both the ways :
1. From device side, you need to configure SNMP view for the only MIB you want access to help-desk and associate it to the community string (snmp v2) or password (snmp v3) they'll use.
For example, as per your last configuration :
snmp-server view Bg123456 iso included
Coinfigure it with only MIB required for this operations:
snmp-server view Bg123456 <mib_name> included
Example :
snmp-server view Bg123456 iso excluded
snmp-server view Bg123456 ifMib included
**ifMIB is needed to do the interface operations, like port shut or no shut etc.
2. From LMS point of view you can configure the user profiles and give them custom authorizations. It is known as user role. A role is a collection of privileges that dictate the type of system access you have. The Manage User Roles workflow allows you to add, edit, copy and delete user-defined roles in LMS.
For more details check here :
http://www.cisco.com/c/en/us/td/docs/net_mgmt/ciscoworks_lan_management_solution/4-2/user/guide/getting_started/lms42_getstart_guide/usrsecmgt.html#wp1072515
-Thanks
Vinod
**Rating is another way to say Thank you. If it helped. **

Similar Messages

  • Nexus Envirometal & Cisco Prime LMS4.2.5 ISSUE

    Hello
    I have 3 cisco nexus 5596 and lms 4.2.5. I need to check the temperature of these nexus devices through LMS but i cannot. For chech the temperature i have to enter the nexus and run the coresponding command sh env. The version of nexus OS is the
    software
      BIOS:      version 3.6.0
      loader:    version N/A
      kickstart: version 5.2(1)N1(1b)
      system:    version 5.2(1)N1(1b)
      power-seq: Module 1: version v5.0
      uC:        version v1.0.0.2
      SFP uC:    Module 1: v1.1.0.0
      BIOS compile time:       05/09/2012
      kickstart image file is: bootflash:///n5000-uk9-kickstart.5.2.1.N1.1b.bin
      kickstart compile time:  9/17/2012 11:00:00 [09/17/2012 21:38:53]
      system image file is:    bootflash:///n5000-uk9.5.2.1.N1.1b.bin
      system compile time:     9/17/2012 11:00:00 [09/17/2012 23:38:22]
    How can i take the results of the sh env command through one poller (Enviromental Template) ?

    Cisco support was able to provide me with a one time download link for DCNM 6.3(2) and the error still persists there. So maybe this isn't an issue of using old software but something else.
    In the device name field I'm putting the IP of our network switch. Is that what we're supposed to use or is that expecting something else?
    Thanks
    Brad

  • Flushing / Deleting Devices from Cisco Prime LMS4.1 - How ?

    Hello,
    Discovery got a little messed up when importing from LMS 3.1
    Basically I want to flush all devices from all the different LMS modules.
    If I delete all devices from Device Management they seem to stay in Topology Services / Device Discovery / Data Collection etc.. They keeps the old device in their own database.
    Is there a way of flushing all devices from all these different modules. I'm going to re-import them with a clean CSV import file.
    Cheers
    Barry

    It is confusing to everybody I think (except perhaps Joe Clarke). Perhaps Joe will jump in with a solution to this last bit.
    Starting back when CiscoWorks instituted a DCR (ca. CiscoWorks 2000?) things began to integrate across the components but under the covers there are still separate bits. Alerts (e.g., those from Fault functions or the old DFM, based on the EMC SMARTS product) are notorious for using settings and a repository different from the rest of the suite. I've had good luck using a local hosts file for that component to work properly (i.e., generate fault records with the proper host name vs. the device IP).

  • Install wildcard SSL on Cisco Prime Infrastructure 1.4

    I'm trying to install a wildcard SSL on a Cisco Prime Infrastrucure 1.4.
    I've manage to install this certificate on the Cisco 5508 WLC, however not so much success with the Cisco Prime.
    There are alot of documentation regarding the installtion of CSR certificates however I could not find anything related to wildcard or public key certificates from Cisco.
    I did find the following from a NetBoyers, I've tried this process however this seems to apply for NCS versions prior to 1.4 as it was unsuccessful
    Any assistance would be creatly appreciated.

    I was able to follow the procedure in the Admin Guide to successfully import and use a CA-issued wildcard certificate (from GoDaddy) with unencrypted private key where the original CSR was not generated by the Prime Infrastructure server.
    Prime needs to be defined with a record in your DNS serving the domain in the wildcard certificate. In my case I am using both an A record and cname alias.
    Following a server restart the wildcard certificate appears fine in Chrome, Firefox and IE when I browse to https://prime.<my_customer's_domain>.
    Below are the commands I used. You would need to have your own certificate and keyfile. My certificate includes the full chain - server certificate, intermediate certificate and root certificate in that order.
    PI01/admin# copy ftp://192.168.254.7/privatekeyplaintext.pem disk:
    Username: admin
    Password:
    PI01/admin# copy ftp://192.168.254.7/gd_bundle-g2-g1.crt disk:
    Username: admin
    Password:
    PI01/admin#
    PI01/admin# root
    Enter root password : 
    Starting root bash shell ... 
    ade # pwd
    /root
    ade #
    ade # cd ..
    ade #
    ade # cd localdisk
    ade # ls -al
    total 68
    drwxr-xr-x 8 root root 4096 Nov 2 09:51 .
    drwxr-xr-x 28 root root 4096 Oct 28 11:22 ..
    lrwxrwxrwx 1 root root 20 Jul 14 13:11 crash -> /opt/CSCOlumos/crash
    drwxr-xr-x 2 root root 4096 Jul 15 23:31 defaultRepo
    drwxr-xr-x 2 root root 4096 Jul 14 13:10 ftp
    -rw-rw-rw- 1 root gadmin 6710 Nov 2 09:51 gd_bundle-g2-g1.crt
    drwx------ 2 root root 16384 Apr 17 2014 lost+found
    -rw-rw-rw- 1 root gadmin 1679 Nov 2 09:50 privatekeyplaintext.pem
    drwxr-xr-x 2 root root 4096 Jul 14 13:10 ssh
    drwxr-xr-x 2 root root 4096 Jul 14 13:10 telnet
    drwxr-xr-x 2 root root 12288 Nov 2 09:57 tftp
    ade #
    ade # mv ./gd_bundle-g2-g1.crt ./defaultRepo
    ade # mv ./privatekeyplaintext.pem ./defaultRepo
    ade #
    ade # exit
    exit
    PI01/admin# show repository defaultRepo
    PI01-140715-0330.tar.gpg
    PI01-140716-0330.tar.gpg
    gd_bundle-g2-g1.crt
    privatekeyplaintext.pem
    PI01/admin#
    PI01/admin# ncs key importcacert wildcardcert gd_bundle-g2-g1.crt repository defaultRepo
    INFO: no staging url defined, using local space. rval:2
    truststore used is /opt/CSCOlumos/conf/truststore
    The NCS server is running
    Changes will take affect on the next server restart
    Importing certificate to trust store
    PI01/admin#
    PI01/admin# ncs key importkey privatekeyplaintext.pem gd_bundle-g2-g1.crt repository defaultRepo
    INFO: no staging url defined, using local space. rval:2
    INFO: no staging url defined, using local space. rval:2
    truststore used is /opt/CSCOlumos/conf/truststore
    The NCS server is running
    Changes will take affect on the next server restart
    Importing RSA key and matching certificate
    PI01/admin#
    PI01/admin# ncs stop
    Stopping Network Control System...
    This may take a few minutes...
    Network Control System successfully shutdown.
    Plug and Play Gateway is being shut down..... Please wait!!!
    Stop of Plug and Play Gateway Completed!!
    SAM daemon process id does not exist
    DA daemon process id does not exist
    DA syslog daemon process id does not exist
    PI01/admin# ncs start
    Starting Network Control System...
    This may take a few minutes...
    Network Control System started successfully.
    PI01/admin#

  • Ask the Expert: Overview of Cisco Prime Service Catalog and Process Orchestrator Solutions

    Welcome to this Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about the Cisco Prime Service Catalog and Process Orchestrator solutions.
    Cisco expert Jason Davis will discuss Cisco’s network management products offered under the Cisco Prime framework. If you have questions about Cisco Prime infrastructure or data center automation with our Cisco Prime Service Catalog and Process Orchestrator solutions, join us on the Cisco Support Community.
    Jason Davis is a distinguished services engineer in the Intelligent Infrastructure Practice team of Cisco Advanced Services. His role is to provide strategic and tactical consulting for hundreds of Advanced Services customers, lead service innovation, and assess new services and technologies. Jason's primary expertise areas are in network management systems, intelligent automation, virtualization, data center operations, software-defined networking, and network programmability.
    Based out of the Research Triangle Park (RTP) campus, Jason is also responsible for administering the Research Triangle Park Network Management Lab, Cisco's largest network management lab.
    Since joining Cisco in 1998, Jason has been a frequent speaker at Cisco's Networkers and CiscoLive conferences in the United States and Europe. In the past five years he has also been involved in the conference network setup and monitoring. He is a much sought-after resource by the field sales teams to assist with presales solutions and executive briefings. He has provided strategic and tactical network management consulting for several hundred customers.
    Jason is a subject matter expert with the following products and features:
    Cisco Prime LAN management solution
    Cisco Prime infrastructure
    CiscoSecure ACS
    Cisco Prime Network Registrar
    Cisco Process Orchestrator
    Cisco Prime Service Catalog
    Cisco IP SLA
    Embedded Event Manager
    SNMPv3
    onePK and OpenFlow
    Cisco UCS
    Device instrumentation
    VMware ESX, ESXi, and vCenter
    ITIL
    Jason received his bachelor of science degree in electrical engineering from the University of Miami (FL). He has been married for 20 years and has 4 children. His interests include providing audiovisual technical support for churches and conference venues, camping and biking with his family, remote-control helicopter piloting, paintball, and recreational shooting.
    Remember to use the rating system to let Jason know if you have received an adequate response.
    Because of the volume expected during this event, Jason might not be able to answer every question. Remember that you can continue the conversation in Data Center > Intelligent Automation under the subcommunity Cisco Prime Service Catalog shortly after the event. This event lasts through September 12, 2014. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

    Hello Jason,
    Thank you very much for welcoming me to your expert discussion :) I feel to be in the right place, at the right time. Thank you also for answering question beyond your scope here, much appreciated. The information received will help me to go further as such I have submitted a 5 start rating for your first reply.
    That sounds promising about the LMS part so yes, I stay tuned and wait patiently.
    Ok, now let’s revert to the actual topic discussed here. Cisco Prime Service Catalog and Process Orchestrator solutions I have briefly read up on this on CCO (where elseJ) and picked out the following quote
    ---- Quote from the Cisco Prime Service Catalog Data Sheet
     Today’s end users want self-service and easy access to IT tools and services.
    Simultaneously, organizations are seeking ways to extend their cloud management
    platforms beyond self-service delivery of virtual machines and infrastructure resources
    while increasing their use of cloud-based solutions to enhance business agility and effectiveness.
    Cisco Prime™ Service Catalog offers tremendous benefits to organizations that want to unify the ways in
    which all types of IT services are ordered and fulfilled, not just infrastructure requests
    ---- un quote ---
    I try to understand what (at high level of course) happens in the back ground when an order is raised and which vendor solution your product can interact with.
    As mentioned in the quoted text, this service catalogue goes beyond the standard infrastructure.
    Let’s say, a user wants to deploy a new email services, or in your example,  extends or create a new web-portal (i.e. for HR to view and manage holiday, staff absence and benefits).
    Your solution will need to interact somehow with the 3rd party vendor application that is capable building such portal I believe.
    Without disclosing to many information, I assume the portal is linked to backend VM,s that spin up requested resources (and more magic of course). Perhaps I am mixing this up with another cisco product where a user can go on the portal and spin up virtual Firewalls, virtual Routers can be provisioned in now time.
    Out if interest; Is this product also known as Mozart? (project code within Cisco?)
    I hope query is ok.
    Best wishes
    Markus

  • Cisco Prime Infrastructure patch 2.1.1 - HA issue

    Hello,
    I have a problem with the Cisco Prime Infrastructure patched to version 2.1.1. I did exactly what Installation Guidelines say:
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/2-1-1/release/notes/cpi_rn.html
    – Install the Prime Infrastructure 2.1.1 patch by using the Administration > Software Updates page on the primary server.
    – Restart the primary server.
    – Verify that the patch installation is complete. If you find the installation complete, decommission and reinstall the secondary server and add it back to the primary server.
    I reinstalled HA server and I'm trying to add it to HA but I get "Failed to authenticate - Primary(xx.xx.xx.xx) and Secondary(xx.xx.xx.xy) PI version does not match"
    Can you help me with that? What I'm doing wrong? or maybe this patch is not prepared to work in HA mode?
    Regards

    Symptom:
    The installation instructions of PI 2.1.1 patch in a High Availability environment are not accurate and following these steps will result in the inability to re-pair the Primary and Secondary servers.
    Conditions:
    If the instructions are followed, then when the user attempts to re-pair the servers, an error will be encountered:
    "High Availability Registration Failed - Failed to authenticate - Primary (x.x.x.1) and Secondary (x.x.x.2) PI version does not match".
    Instead, the following steps have proved to work correctly:
    1. Upload and install patch on primary.
    2. Upload and install patch on secondary.
    3. Stop NCS services on secondary
    4. Stop NCS services on primary
    5. Start services on secondary
    6. Start services on primary
    7. Re-pair HA servers from primary
    Workaround:
    Workaround 1:
    On the secondary, go under root and issue:
    # cd /opt/CSCOlumos/bin/
    # ./hamode.sh primary
    Answer 'yes' when prompted.
    Go to admin user and execute
    # ncs stop
    After the services are stopped:
    # ncs start
    When the services are back up, login to the secondary GUI as you would login to a primary server
    Go under Administration > Software update, upload the patch and install it.
    Go to admin user and execute
    # ncs stop
    After the services are stopped:
    # ncs start
    When the services are up, go under root and issue:
    # cd /opt/CSCOlumos/bin/
    # ./hamode.sh secondary
    Answer 'yes' when prompted.
    Go to admin user and execute
    # ncs stop
    After the services are stopped:
    # ncs start
    After the message that services started successfully on the secondary, initiate a new High Availability configuration from the primary. Now the synchronization between the two servers should succeed.
    Workaround 2:
    Redeploy or reinstall the Primary server, restore the backup which was taken prior to applying the patch, reconfigure the High Availability and continue with the steps described in the Conditions section.
    Further Problem Description:
    Release Notes have been updated with more precise instructions.
    Known Affected Releases:
    (1)
    2.1(0.0.85)

  • Discount L-PI12-1.5K-UP (LMS 2.x/3.x to Cisco Prime Infrastructure 1.2 Maj Upg 1500 Device)

    Hello everyone,
    Last month I was in London (Cisco Live 2013) I have spoken with a Cisco Prime (BU) Specialist. He told me verbally that there is currently a 75% discount for L-PI12-1.5K-UP. Can anyone confirm this and tell me what the part number is?
    Thanks !
    Gertjan Scharloo

    you would need to contact your Cisco Partner/SE to be able to get those details.
    HTH,
    Steve
    Please remember to rate useful posts, and mark questions as answered

  • Cisco prime 2.2.0 "Telnet/SSH : Unreachable"

    Hi,
    I've installed the Cisco Prime 2.2.0 OVA (VMware) and ran discovery with a Credential Profile.
    some of the device has discovered with complete state and some with Partial Collection Failure state.
    when trying to edit the device (under network inventory) and verify credentials i'm getting the above error "Telnet/SSH : Unreachable", but when SSH from the Cisco Prime CLI with the same credentials all works just fine.
    %SSH-5-SSH2_SESSION: SSH2 Session request from X.X.X.X (tty = 1) using crypto cipher '', hmac '' Failed
    please help...
    10x
    Eyal

    Hi Afroz,
    All of my net devices use AAA for login.
    I'm using credentials profile to discover my devices and some of them has discovered as they should and some of them are partialy discover with the Cisco Prime log it with CLI/ssh issue.
    But when I'm SSH to the partialy discovered device via the Cisco Prime CLI with the same credentials as configured at the credential profile, I'm able to login with no issue.
    Please note - while I'm editing the partialy discovered device and testing the credential via the Prime GUI, it display the error message "Telnet/SSH : Unreachable" - and the device log meeage is %SSH-5-SSH2_SESSION: SSH2 Session request from X.X.X.X (tty = 1) using crypto cipher '', hmac '' Failed.
    What does it mean?
    10x
    Eyal

  • Cisco Prime device challenge

    How do I connect via server console to cisco prime infrastructure?
    I can ssh and telnet to it.
    What happens if the CPI is  not  pingable?
    Kindly revert,
    Regards,
    Tioluwani

    Please see a description of the issue below as regarding my first discussion above
    a description of the problem(s)I am facing with the Cisco Prime device.
    I can't connect to it via the web management interface
    It takes several attempts to boot the device... most cases it hangs in the initial stages of booting. At times it is able to boot into console mode. 
    ​I would appreciate if someone could come and look at the device
    Regards,
    Tioluwani.

  • Cisco Prime Assurance

    New install with a Cisco Prime Assurance 9.0. I am able to log into the CLI with SSH but the web page using https://IPADDRESS does not give me access - message "This page cannot be displayed". I've restarted the VM and services are running. I installed the provisioning server without issue.                 

    NO, Cisco Prime Assurance Manager is upgraded and replaced by Cisco Prime Infrastructure. Refer the notice :
    http://www.cisco.com/c/en/us/products/cloud-systems-management/prime-assurance-manager/index.html

  • Problem Exporting Backups from Cisco Prime LMS 4.2 deployed as software appliance

    Hi,
    I'm trying to backup a Cisco Prime LMS4.2 based on soft appliance. I have the backup stored on destination disk://localdisk/backup/, but i can't export it via FTP to external server. When I perfrom the transfer only the folder is stored in the destination path, the files aren't included. I think that i have to compress files on the backup folder as .tar file using linux shell, but i can´t find the backup folder from this shell.
    It´s correct my procedure, if not What is the procedure and commands to export a backup to external server via FTP?
    Thanks,

    Hi Dave,
    If your Goal is to upgarde the IOS of  the devices via LMS  then  MANUALLY download the IOS Image from cisco.com
    and use the FILE SYSTEM option to add the Image in the Software Repository
    Then try to upgrade the IOS and see how it works.
    Thanks
    Afroz

  • Difference between cisco prime NCS and cisco WCS

    hello
    i have a question. I am just started with testing cisco prime ncs
    i have worked with cisco WCS
    now i was wondering wat the difference is between these two
    can someone please explain it.
    thanks allot

    They are both very similiar in functionality.  The major difference is that NCS offers a basic switch management front end and allows you to see your wired clients just as you would your wireless.  Other then that, the I've found the latest version of NCS to run quite a bit smoother and faster then my WCS install of several years, slicker graphics.  I would recommend using NCS in Chrome for the best view.

  • Cisco Prime not booting

    Hi Team,
    I kindly need your help regarding the issue below:
    a description of the problem(s)I am facing with the Cisco Prime device.
    I can't connect to it via the web management interface
    It takes several attempts to boot the device... most cases it hangs in the initial stages of booting. At times it is able to boot into console mode. 
    ​I would appreciate if someone could come and look at the device
    Regards,
    Tioluwani.
    Kindly assist.

    Please I have not seen any response yet.
    All the people who respond here are volunteers:  We are not paid by Cisco and we are here during our free time.  
    If you seek immediate answer, please open a TAC case.  

  • Question of Cisco Prime

    Hi everybody.
    I have one question about cisco prime infraestructure, i whish to know how the Cisco Prime control the link WAN of my enterprise.
    the topology is:
    ROUTER --> MODEM --> ISP
    I supossed that CP must have the assurance lincense, for use the control with netflow, but i whish to know how i can monitored the link between the modem and the ISP with the cisco prime.
    i can monitored the link with the soft. Intermapper, i whis to know if the Ciso Prime 1.2 could perform this action.
    Regards

    Well the situation is like this... I am monitoring several wireless network devices. Some are connected by 3G and others via some other technology.
    As you probably already know wireless connections are situational. Sometimes they work and sometimes they don't. What I want to achieve is to reduce the number of false positive alarms from these devices.
    The current plan is to increase the timeout to the maximum (60 seconds) and the number of retries to a high enough number to make false positives statistically unprobable.
    I would still like the devices to get polled quite often for a quick response, for example each 4 minutes (240 seconds).
    The optimal situation would be the following:
    Poll repeatedly each 4 minutes...
    For each successful poll, the timer resets and after 4 minutes another poll happens, except for when the poll is not successful. When this happens no new polling instances get started and the polling instance that failed continues with a timeout of 60 seconds for X number of repetitions.
    As soon as one of the retries is successful, the timer resets and in 4 minutes time a new polling instance gets created anew. If however after all of the retries, the device still fails to respond to the polls an alarm should get created and in 4 minutes time, it's time to check if the connectivity has been restored.
    Hopefully the image is a little clearer now... This is why I'm interested in understanding if new polling instances get started independently or not.

  • Limit Syslog DB size Cisco Prime

    Hi All,
    I have an issue with my Cisco Prime 4.1.
    I have a log file for syslog who’s getting bigger and bigger every day. We have created a purge policy to limit the size to 1 gigabyte. This seamed to be a good solution.
    But at the same time, I have a database located under Cscopx/database/rmeng/syslog.db, in three parties, syslogfirst, second and third. The problem is that those files grow and never stop growing (5GB and more), until the disk space is full.
    At the start the syslog db didn't grow anymore since I configured the purge job for the syslog file. But after a while the syslog db began to grow again.
    Are those 2 (syslog file and DB) related in any way? Does anyone has the same problem? I suppose there is an easy way to limit the size of the syslog db.
    Thanks,
    Best Regards,
    Joris                  

    Syslog.log and Syslog*.db are connected to each other. Syslogs sent from device are received in syslog.log and then processed and written in syslog db. All syslog reports come from Db.
    To control the log file the logrot utility is used and to control the db the syslog purge and other administrative fuctions are used.
    For more details on logrot configuration see :
    http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_lan_management_solution/4.1/user/guide/admin/server.html#wp1055307
    For details on administring syslog see :
    http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_lan_management_solution/4.1/user/guide/admin/purgeset.html#wp1060237
    Attached is an Syslog Acrhitecture for LMS, hopefully it will be helpful.
    -Thanks

Maybe you are looking for

  • 10.6.8 update causes bluetooth to repeatedly "crash" while using headphones

    I'm having severe problems with bluetooth "crashing" during headphone use, causing bluetooth to become "bluetooth not available". This problem is very frustrating, causing me to stop using my Sony DR-BT101 headphones with my iMac. I've tried resettin

  • Boot Camp 5 Windows 8 partition

    So I haven't dual-booted in a while, I used to run Windows 7 Ultimate. Boot Camp worked fine. I recently have been trying to install Windows 8 Pro and Boot Camp just will not partition my drive. It keeps saying "An error occurred while partitioning t

  • Error in web reports (Report 10g r2)

    Hi, I am working on Developer 6i and has started learning 10g. I created a web report.If i run it in there is an error in web report. 500 Internal Server Error OracleJSP: oracle.jsp.provider.JspCompileException: Errors compiling:C:\Users\USER\AppData

  • Wie bekomme ich das aktuelle Camera Raw 8.7.1 Modul in meine CS5????

    Wie bekomme ich das aktuelle Camera Raw 8.7.1 Modul in meine CS5????

  • TACACS+ packet from unknown Network Device or AAA Client

    Hi all, I can't perform login using the credential set at ACS server, From the log it shown: "Failure Reason: 13017 Received TACACS+ packet from unknown Network Device or AAA Client" I know there's some changes on TACACS+ part for new catalyst IOS, s