Symantec Backup Remote Agent Failing

Hello,
N00b here. My IT Support at my company has Symantec Backup Exec 12 for Windows Servers setup to backup our Macs. Their saying on my Mac, the backup remote agent keeps failing. It fails randomly. Sometimes it will be working for 2 weeks and then all of a sudden it fails. He says he usually has to go into Terminal and run the following commands if the agent has failed to restart it:
cd /Library/Startupitems/VRTSrams
sudo ./VRTSrams start
Can anyone help me to why it's continuously failing? If this is the wrong forum, don't shoot me.
Thanks in advance.

~Bee wrote:
Norton stuff has a glorious reputation for messing up Macs.
This is not Norton the OP is referring to. This is the client for Symantec's BackupExec application...entirely unrelated to Norton. So please don't give false hope for software the OP is not even using.
Now... Rockets4Life,
What version of BackupExec are you running? We run 11d and 12.5 without issues on Macs, so you may want to look into upgrading if possible. However, we did see the same issue you're seeing on one of our Linux boxes and doing a Google search showed that it was a common issue among Linux installations.
We remedied by configuring the Linux box to run a cron task every 15 minutes to run the RALUS startup command and it worked fine ever since. You may want to try the same.
Also, you should also post your question on Symantec's forums, as if there is a definitive solution, you'll probably find it there: http://www.symantec.com/connect/forums

Similar Messages

  • Failed to send SLD settings to remote agent

    Dear Guru's,
    I'm facing problem when trying to register SLD Agent. I have run this command :
    /smdsetup.sh sldconf , /smdsetup.sh managingconf and etc but nothing is worked for me.
    after i have run those command, Agent is available within system, but when i tried to push SLD Setting i got this error :
    "Failed to send SLD settings to remote agent (detail: Failed to save new SLD settings; nested exception is: java.lang.Exception: Unexpected error while changing SLD settings - exit code: -1)"
    I just update the Solution Manager ABAP SPS11, but my JAVA SPS is still 07.
    Is it because i don't upgrade my Java ?
    My DAA Agent is 7.20 patch level 87.
    kindly need your help to enlighten me about this issue, i cannot move to other configuration because this error.
    thankyou.
    Best Regards,
    Marvin

    Hi Marvin,
    Can you explain in details which system are you trying to connect with some screenshot and logs.
    Are you trying to connected a non-ABAP/non-AS-java system ?
    If yes, you check this thread.
    http://scn.sap.com/community/netweaver-administrator/blog/2013/08/11/trex-configuration-with-solution-manager-71--part-1
    Also, check this sap KBA for more information.
    1147499 - Connection to the System Landscape Directory
    If you are registering DAA of SLD.
    then Use below command
    smdsetup managingconf hostname:"sapms://<fqn>" port:"<MS httpPort>" [optional user:"<...>" pwd:"<...>" servername:"<...>"]
    smdsetup managingconf hostname:"<fqn>" port:"<p4 port>" [optional user:"<value>" pwd:"<value>" servername:"<value>"]
    If this is also not working,
    Execute the command
    smdsetup supportlogs
    At the end of the execution of the command, a Zip file is generated in at the following location: /usr/sap/<AGENT_SID>/<AGENT_INSTANCE_NUMBER>/SMDAgent/supportLogs_<TIMESTAMP>.zip.
    Ans share the zip file.
    Regards,
    Divyanshu

  • Urgent!! Setup of SMD Agent failed due to Remote Error....

    I am getting the following error when i tried to Setup the Smd agent using setup wizard:
    <b>The assignment of server frces4153 to SMD Agent failed
    Remote error occurs during the connection to the smd agent for agent frces4153</b>
    Can you please give me the solution for this...
    <b>Reward points of all the replies....</b>
    Ajay Kande

    Thnx for ur suggestions, Now i colud see the following error "[Setup]Failed to assign SMD Agent to frces4146/EP7 (frces4146)
    [EXCEPTION]
    Time out occurred when calling method 'getService' on object [com.sap.smd.api.IAgentContext_Stub@7fc07fc] after 10000 ms.... [siehe Details]
    from the logs....
    Ajay Kande

  • Remote Agent: OLT returns Version Check Failed to Match

    I am attempting to use remote agents. I have tried both Windows and Linux agents with identical results.
    After running a test with one of the remote agents the server shows:
    Status Current Error
    Orphaned Agent Version Check failed to Match
    Client shows:
    18:19:04,198 INFO [Messenger] Try server=t3://192.168.32.102:8088 queue=queue/AgentPoolNotificationQueue
    18:19:04,259 INFO [Messenger] Got ConnectionFactory
    18:19:04,273 INFO [Messenger] Got queue queue/AgentPoolNotificationQueue
    18:19:04,291 INFO [Messenger] Created queue connection.
    18:19:04,304 INFO [Messenger] Created queue session.
    18:19:04,316 INFO [Messenger] Connected to server=t3://192.168.32.102:8088 queue=queue/AgentPoolNotificationQueue
    18:19:04,316 INFO [Request] [URL:t3://192.168.32.102:8088;Requestor Username: oats;Requestor Key:99bb5c62-f65a-4dbc-b8cb-db44bbd3ece4;Requestor Queue:queue/AgentPoolNotificationQueue;Request ID:6;Request:stopagent;] - authentication successful
    18:19:04,316 ERROR [EmpStartMain] Unknown agent ID: agId14_rnda167a6bd-2f25-4be8-b449-903b9bb7cd40
    Any help is much appreciated. Searched Metalink and didn't find anything on this specific error.
    Thanks,
    John A. Booth
    http://www.metavero.com

    The wording in the original error "Version Check failed to Match" makes me think this is similar to something I encountered once after installing a small patch release. You need to make sure the Agent installed on the remote machine is the same version as the controller.
    e.g. If you had installed OATSv9.00 on both controller and agent machines and then upgraded JUST the controller to OATSv9.01 the controller would no longer be able to talk to the v9.00 agent on the remote machine.
    I could be wrong, but that's essentially what I found with one of the earlier v8 upgrades.
    Try upgrading the agent on your remote machine(s) with the same installation you have on your controller (but only install the agent, not the whole OATS paclage).
    Edited by: IHodgetts on Jan 28, 2010 4:55 PM

  • Cisco WAAS moibile integrated with Symantec Backup Exec 2010

    Here customer requirement is to take backup of opened Database file .fdb
    (Microsoft Dynamic Navision) integrated with WAN optimization (Cisco WAAS
    mobile).
    Problem is  Cisco WAAS mobile is not optimizing  Symantec backup process when backup job is running.
    Please find attached files (WAAS mobile accleration status with symantec
    backup process).
    Customer is using Microsoft Dynamics Navision (ERP application).
    WAAS mobile client is connecting and file copy is accelerating, but
    symatec backup (beremote.exe) and Navision (fin.exe) processes are not
    accelerating.
    I added above processes in WAAS mobile server's acceleration list.
    Please advise if any changes has to made in WAAS mobile server.
    Regards
    Prasad
    Cell: 9000012355

    Hi Prasad,
    According to the screen shots provided the fin.exe process is bypassed due to Low Latency.  From the admin guide this means:
    Bypassed : Low Latency. The latency between the client and the application server is less than the latency threshold, which is 10 ms by default. This threshold may be modified on the Connection Settings tab on the Configure > Clients > Networking page.
    Also, I see SERVER.exe process is going to the same server or subnet as fin.exe but is bypassed due to Pre-Existing connection.
    Bypassed: Pre-existing Connection. When WAAS Mobile is started after other applications, the existing TCP connections associated with those applications will not be reset unless the “Auto Reset Connection” property has been selected for the process in the Accelerated Processes table, and hence, these pre-existing connections will be bypassed.
    Lastly, I see bermote.exe is listed as Bypass Reason Unknown in one of the screen shots.
    Bypassed : Reason Unknown. This message will occur when an attempt to reset a TCP connection associated with an application that has been configured to have these connections be automatically reset (via the Accelerated Processes table on the Configure > Clients > Acceleration page) fails.
    Is this client actually accessing a server that is remote for these first two processes?
    For the last process, did we try to first exit the application in question and all the associated processes (beremote, and any other processes that may get started with this application), then start the WAAS Mobile client, then finally start the associated process/application?
    Cheers,
    Mike Korenbaum
    P.S.  If this answers your question please mark it as such.

  • Exchange backup Issue with Symantec Backup Exec 2014

    https://support.symantec.com/en_US/article.TECH211305.html
    Have you looked at this article? Do you have the remote agent installed? I would see if there is updates for the agent as well( Right click the exchange server from your console and hit update).

    Hi,
    I am using Symantec Backup Exec 2014 software.  I want to take the daily backup of our Exchange database (Exchange 2013).  But I cannot add the Exchange database to the Backup process.
    I tried Add server wizard and connect exchange from the server wizard.  But both options are not working.  But I can take the backup of files that stored in the same server (exchange).
    Please help...
    Thanks
    KK
    This topic first appeared in the Spiceworks Community

  • Back up MaxDB thru Symantec Backup Exec

    Hi everyone,
    I've just installed a 64-bit unicode SAP ECC 5.0 on MaxDB 7.5 in Windows 2003 x64 Enterprise.
    I am now trying to figure out how to configure Symantec Backup Exec 11d to work with MaxDB so that I can do online backups. I heard that it is directly not possible, but is there a workaround for this?
    Any help would be appreciated.
    Thanks,
    Joseph

    Hi Andreas,
    That was a very good document that you recommended. It is clear enough. But the thing is I don't think NetBackup is installed to the server. The SAP-relevant options licensed and installed by the vendor for Backup Exec 11d are:
    1. Agent for Oracle on Windows Servers
    2. Agent for MS SQL Server
    2. Agent for MS SQL Server 2000
    3. Agent for SAP Applications
    4. Backup Exec for Windows Servers
    5. Remote Agent for Windows Servers
    Do I have to install NetBackup or does it have a counterpart in 11d?
    Thanks again,
    Joseph

  • Server backup Faliure Wth failing with snapshot error

    Hi Team ,
    One of my VM guest Machine's backup job is getting failed again and again with snapshot error .
    When I checked logs I can see Event Warning  " VM disks consolidation failed "  where currently there is no snapshot is available  on this machine.
    But When I manually run the snapshot by using by using quiesce Method and then again run backup Job from Symantec , Backup runs fine 7
    We are using Symantec Netbackup 7.6.1 and My VM Machine is running on ESXi01 , VM version 9 , Guest OS MS Windo 2008 R2
    Any Help Would be really appreciate

    Hi,
    DO THIS FIRST
                 a) Try to do a storage vMotion of that VM and delete the file which are left behind along with the VM folder (if any )
                 b) Take a VMware snapshot and after completion , Go for DELETE ALL --> This will update the snapshot records in the VMX file and snapshot configuration file with latest number which is unique while taking the snapshot as per the process.
    DO THIS AFTERWARDS
               a) STOP and set to manual service for Volume shadow copy ,VMware snapshot provider and Virtual Disk inside the Guest OS. Wait and Check for schedule backup.

  • 802.1x and Remote Agent

    AD 2000 Domain, ACS appliance (running 3.3.1), remote agent on the Certificate authority. setup PEAP per instructions.
    When i try to login with a user on a desktop, it errors out. This is the error message i see in the RemoteAgent logs
    CSWinAgent 02/03/2005 17:13:56 A 0048 0604 NTLIB: Attempting Windows authentication for user RFI5771
    CSWinAgent 02/03/2005 17:13:56 A 0048 0604 NTLIB: Windows authentication SUCCESSFUL (by DC1)
    CSWinAgent 02/03/2005 17:13:56 A 0048 0604 NTLIB: Obtaining RAS information for user RFI5771 from DC1
    CSWinAgent 02/03/2005 17:13:56 A 0048 0604 NTLIB: NetUserGetLocalGroups failed with result [5]
    CSWinAgent 02/03/2005 17:13:56 A 0048 0604 NTLIB: nt_GetUsersNTGroups failed
    Its funny. With my ID, everything works (dot1x gets authenticated, dynamically assigned VLAN, properly authenticated.
    But I can't get it to work with any other user. Thinking that there was a rights issue Service account, i tested with a Domain admin account. No avail.
    Any thoughts? I tested this whole setup in a lab with ACS for windows and it works like a charm. Getting it to work with the appliance has been a bit challenging.

    Hi,
    Did you ever get to the bottom of this issue. I have the same issue with ACS 3.3.3 for windows. I have not seen this issue on any other ACS Win / Appliance installs.
    Thanks in advance
    Allan

  • Whole online backup from DB13 failed due to processing error

    Hello!
    I have difficulty by execution of Whole database online backup from DB13 via FTP on the remote target.  The backup goes very slow and breaks after a while.
    The BRBACKUP action log looks as follows:
    backup_mode ALL
    backup_type online
    backup_dev_type stage
    stage_root_dir /sap/DEVB
    compress no
    stage_copy_cmd ftp
    remote_host 192.168.200.3
    remote_user sapbackup
    #FILE..... E:\ORACLE\DEV\SAPDATA2\SR3_10\SR3.DATA10
    #SAVED.... /sap/DEVB/bdwkuudu/SR3.DATA10 #1/6
    BR0280I BRBACKUP time stamp: 2007-10-23 01.44.35
    BR0063I 6 of 41 files processed - 12000.047 MB of 93092.766 MB done
    BR0204I Percentage done: 12.89%, estimated end time: 23:06
    BR0001I ******____________________________________________
    BR0202I Saving E:\ORACLE\DEV\SAPDATA2\SR3_6\SR3.DATA6
    BR0203I to /sap/DEVB/bdwkuudu/SR3.DATA6 ...
    #FILE..... E:\ORACLE\DEV\SAPDATA2\SR3_6\SR3.DATA6
    #SAVED.... /sap/DEVB/bdwkuudu/SR3.DATA6 #1/7
    BR0280I BRBACKUP time stamp: 2007-10-23 02.38.05
    BR0063I 7 of 41 files processed - 14000.055 MB of 93092.766 MB done
    BR0204I Percentage done: 15.04%, estimated end time: 21:36
    BR0001I ********__________________________________________
    BR0202I Saving E:\ORACLE\DEV\SAPDATA2\SR3_7\SR3.DATA7
    BR0203I to /sap/DEVB/bdwkuudu/SR3.DATA7 ...
    <b>BR0278E Command output of 'F:\usr\sap\DEV\SYS\exe\uc\NTAMD64\sapftp.exe -v -n -i 192.168.200.3 -u H:\oracle\DEV\sapbackup\.bdwkuudu.ftp -b -c put E:\ORACLE\DEV\SAPDATA2\SR3_7\SR3.DATA7 /sap/DEVB/bdwkuudu/SR3.DATA7':
    Connected to 192.168.200.3 Port 21.
    220-FTP server ready.
    220 This is a private system - No anonymous login
    331 User sapbackup OK. Password required
    230-User sapbackup has group access to: administrator
    230-This server supports FXP transfers
    230-OK. Current restricted directory is /
    230-************************************************
    230-* Use SITE command to change client codepage: *
    230-* ie, site codepage [client codepage] *
    230 ************************************************
    200 TYPE is now 8-bit binary
    200 PORT command successful
    150 Connecting to port 4977
    NiWrite error: -6, bytes to send: 32767 bytes written: 0
    BR0280I BRBACKUP time stamp: 2007-10-23 03.08.37
    BR0279E Return code from 'F:\usr\sap\DEV\SYS\exe\uc\NTAMD64\sapftp.exe -v -n -i 192.168.200.3 -u H:\oracle\DEV\sapbackup\.bdwkuudu.ftp -b -c put E:\ORACLE\DEV\SAPDATA2\SR3_7\SR3.DATA7 /sap/DEVB/bdwkuudu/SR3.DATA7': 1
    BR0222E Copying E:\ORACLE\DEV\SAPDATA2\SR3_7\SR3.DATA7 to/from /sap/DEVB/bdwkuudu/SR3.DATA7 failed due to previous errors </b>
    BR0280I BRBACKUP time stamp: 2007-10-23 03.08.43
    BR0317I 'Alter tablespace PSAPSR3 end backup' successful
    BR0056I End of database backup: bdwkuudu.ans 2007-10-23 03.08.37
    BR0280I BRBACKUP time stamp: 2007-10-23 03.08.43
    BR0054I BRBACUP terminated with errors
    Any helpful information will be appreciated.
    regards!
    Thom

    this post is duplicated at Re: Backup to remote stage failed due to RFC error
    please only post your question once and only in 1 forum.
    thanks.

  • "Mirror agent failed to quit"

    i recently posted a question about what may be causing my imac to freeze while shutting down ... or at least take a really long time to shut down. i got a lot of good advice on potential problems, i ran the disk utility, fixed permisions, and disk errors.
    i decided to run updater, and after installing a security update, when my computer tried to restart it gave me the following message:
    "mirror agent failed to quit...(and then something like shutdown timed out)"
    is this a problem? any way to fix it?
    thanks
    brett

    brett,
    According to QuickTimeKirk, The "Mirror Agent" is the software that keeps your local copy of your iDisk in "sync" with your remote copy.It could be that you had made changes at Homepage and the files had not yet been "synced" to your local copy. If it happens often you can turn off the "automatic" syncing feature.;~)

  • ORA-28511: lost RPC connection to heterogeneous remote agent using

    hi,
    I have configured dblink between Oracle and sqlserver using "Oracle Database Gateway for SQL Server" method.
    i am following the below listed documents
    ID 437374.1---How to Setup DG4MSQL (Oracle Database Gateway for MS SQL Server) Release 11 on Linux
    http://download.oracle.com/docs/cd/B28359_01/gateways.111/b31042/configsql.htm
    All the steps have done and listener, tns also working fine. but, retrieve the data from sqlserver its shows following error.
    SQL> select from "demo"@slink;*
    select from "demo"@slink*
    ERROR at line 1:
    ORA-28511: lost RPC connection to heterogeneous remote agent using
    SID=ORA-28511: lost RPC connection to heterogeneous remote agent using
    SID=(DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=erpdev01.4iapps.com)(PORT=1511))(C
    ONNECT_DATA=(SID=dg4msql)))
    ORA-02063: preceding line from SLINK
    Process ID: 25158
    Session ID: 298 Serial number: 5602
    System Details:
    Oracle Database :
    OS : Enterprise Linux Enterprise Linux Server release 5.2
    DB Version : 11.1.0.7.0 Enterprise Edition Release
    Oracle Database Gateway for SQL Server version : 11.1.0.6.0
    Sqlserver Database :
    OS : windows xp
    DB Version : sql server 2005 express edition
    kindly share your ideas....
    Thanks in advance

    Hi,
    To follow up could you please provide the following information -
    - the gateway listener.ora
    - gateway init<sid>.ora
    - gateway tnsnames.ora file
    - create database link statement
    - a gateway debug trace from the failing select. Add the following to the gateway init<sid>.ora file -
    HS_FDS_TRACE_LEVEL=debug
    and issue a select from a new SQLPLUS session, then end the session.
    Are the gateway and the RDBMS in the same or different ORACLE_HOME directories ? The gateway is at a lower version than the RDBMS so you should apply the 11.1.0.7 patchset to the ORACLE_HOME where the gateway is installed, to bring it to 11.1.0.7.
    Regards,
    Mike

  • Lost RPC connection to heterogeneous remote agent....

    I'm trying to establish a db link to a Sybase server however i'm constantly presented with a ORA-28511 error. I've searched all over the place for solutions and nothing seems to work.
    Can some on please help diagnose this.
    <tnsnames.ora>
    AUSPROFILE=
    (DESCRIPTION =
    (ADDRESS_LIST =
    (ADDRESS = (PROTOCOL = TCP)(HOST = au-par-orasrv)(PORT = 1521))
    (CONNECT_DATA =
    (SID = TG4SYBS)
    (HS=OK)
    <listener.ora>
    LISTENER =
    (DESCRIPTION_LIST =
    (DESCRIPTION =
    (ADDRESS_LIST =
    (ADDRESS = (PROTOCOL = IPC)(KEY = EXTPROC0))
    (ADDRESS_LIST =
    (ADDRESS = (PROTOCOL = TCP)(HOST = au-par-orasrv)(PORT = 1521))
    SID_LIST_LISTENER =
    (SID_LIST =
    (SID_DESC =
    (SID_NAME = TG4SYBS)
    (ORACLE_HOME = D:\oracle\ora92)
    (PROGRAM = TG4SYBS)
    <inittg4sybs.ora>
    # HS init parameters
    HS_FDS_CONNECT_INFO=p7austest.p7austest
    HS_FDS_TRACE_LEVEL=OFF
    # Environment variables required for Sybase
    set SYBASE=D:\\Sybase
    set SYBASE_OCS=OCS-12_5
    A TNS ping to AUSProfile is successful however if I try and execute select * from all_catalog@ausprofile, the error above is returned.
    Thanks

    Here's the details on the error message:
    28511, 00000, "lost RPC connection to heterogeneous remote agent using SID=%s"
    // *Cause:  A fatal error occurred in one of the following places:
    //          -- the connection between the ORACLE server and the agent
    //          -- the heterogeneous services remote agent itself
    //          -- the connection to the non-Oracle system
    //          This error occurred after communication had been established
    //          successfully.
    // *Action: Check for network problems and remote host crashes. The problem is
    //          probably in the agent software. If so, contact a customer support
    //          representative of the agent vendor.In my experience, this is usually caused by the OTG agent process failing.
    Simple explanation - your db link to the OTG gateway connects to an Oracle listener that starts up an agent process. This process connects to the foreign database and acts as the gateway between your end and the foreign database. When this agent process fails, your side realises that the remote process is no more as it is no longer responding. The above error is then raised - as all your side knows that something critical went wrong on the agent side.
    This agent has its own +.ora+ configuration file. One of the parameters that can be set is HS_FDS_TRACE_LEVEL (just confirm it for your OTG version - been years since I last used OTG). When the agent give problems, enable this parameter and have a look at the trace file generated by the agent process. The reason for the agent process failing should be listed in the trace file.

  • Windows Remote Agent Failover timeout (ACS 4.2)

    Hey everybody,
    I'm using two Windows 2003 Servers with local users as External User Databases (so they're both usind the \LOCAL domain) for my ACS 4.2 appliance. I've added the machines as Windows Remote Agents and configured them as Primary and Secondary Remote Agents. In general, all this works great including the failover. However, if the primay machine actually fails, it takes about 10 - 15 minutes until the ACS uses the secondary server for authentication. Is there any way to adjust the failover timers? As far as I understand, the Remote Agent response timeout setting on the Remote Agent selection page is only for retrieving the Windows groups for group mapping. I've lowered this setting but it didn't have an effect on my problem.
    Can anybody tell me more about the failover mechanism here? Does the ACS simply wait for the Primary Remote Agent for a while and then proceed to the Secondary? How long is failover supposed to take? Can any adjustments be made?
    Any hints will be much appreciated!
    Matt

    Hi,
    sorry for the long delay, it took a while to collect the necessary data.
    A few comments on the logs. I've abbreviated them to the relevant parts (in my opinion) to make things a little easier to find.
    Also, I had to change IP addresses and hostnames (but kept them consistent to represent our actual IP settings).
    This is our set-up:
    Hostname
    IP Adress
    ACS
    10.10.10.10
    CSWinAgent_1
    10.11.11.16
    CSWinAgent_2
    10.10.10.16
    Please note that the system clocks are not in sync. I've tried to help with some comments in the logs (marked with ***)
    I tested the following:
    1. Only CSWinAgent_2 is running, everything working fine.
    2. Also started CSWinAgent_1 (see log at 21:47:14)
      -> authentication still working (not in the logs)
    2. Shut down the service on CSWinAgent_2 (21:52:37)
    3. 5 unsuccessful authentication attempts for 15 minutes (see ACS log)
    4. First successful attempt (ACS log, 22:06:33)
    5. Another fail (strange) and successful login from another client (ACS log, 22:08:01)
    6. Shut down the service on CSWinAgent_1 (22:04:47)
    7. Started the service on CSWinAgent_2 (22:09:48)
    8. Failed attempt (ACS log, 22:09:03)
    9. Successful attempt after < 1min (ACS log, 22:09:11)
    I would appreciate any ideas and information on how and in which timeframe the switchover process is supposed to work.
    Thank you very much for your help.
    Matt
    Here are the logs:
    ACS (10.10.10.10):
    *** 5 failed login attempts over 15 minutes (CSWinAgent_1 is available during this time):
    Jul 13 21:51:55 10.10.10.10 CisACS_02_FailedAuth 1oz5bgsae 1 0 Message-Type=Authen failed,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Authen-Failure-Code=External DB is not operational,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,
    Jul 13 21:52:01 10.10.10.10 CisACS_02_FailedAuth 1qn2vrgaf 1 0 Message-Type=Authen failed,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Authen-Failure-Code=External DB is not operational,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,
    Jul 13 21:52:53 10.10.10.10 CisACS_02_FailedAuth 61f498ag 1 0 Message-Type=Authen failed,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Authen-Failure-Code=External DB is not operational,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,
    Jul 13 21:56:41 10.10.10.10 CisACS_02_FailedAuth 1xaujikah 1 0 Message-Type=Authen failed,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Authen-Failure-Code=External DB is not operational,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,
    Jul 13 22:06:32 10.10.10.10 CisACS_02_FailedAuth k6ymh8aj 1 0 Message-Type=Authen failed,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Authen-Failure-Code=External DB is not operational,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,
    *** 2 successful, 1 fail (See 22:02:53 & 22:04:20 on CSWinAgent_1):
    Jul 13 22:06:33 10.10.10.10 CisACS_01_PassedAuth kgy7v0ak 1 0 User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,Filter Information=Access Filter Deny_RZ-SAN from USER_GROUP did not fail any criteria. This is sufficient to satisfy an 'Any Selected' SPC NAR config.,
    Jul 13 22:06:34 10.10.10.10 CisACS_04_TACACSAcc kqxt8sal 1 0 Group-Name=USER_GROUP,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,NAS-Portname=tty1,Caller-Id=192.168.1.6,Acct-Flags=start,service=shell,task_id=196,
    Jul 13 22:06:40 10.10.10.10 CisACS_02_FailedAuth mevdjgam 1 0 Message-Type=Authen failed,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Authen-Failure-Code=External DB is not operational,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,
    Jul 13 22:08:01 10.10.10.10 CisACS_01_PassedAuth 18vyhjgan 1 0 User-Name=USER_ID,NAS-IP-Address=172.16.1.139,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,Filter Information=Access Filter Deny_RZ-SAN from USER_GROUP did not fail any criteria. This is sufficient to satisfy an 'Any Selected' SPC NAR config.,
    Jul 13 22:08:01 10.10.10.10 CisACS_04_TACACSAcc 18vyhjgao 1 0 Group-Name=USER_GROUP,User-Name=USER_ID,NAS-IP-Address=172.16.1.139,NAS-Portname=tty1,Caller-Id=192.168.1.6,Acct-Flags=start,service=shell,task_id=134,
    Jul 13 22:08:03 10.10.10.10 CisACS_04_TACACSAcc 19fxob0ap 1 0 Group-Name=USER_GROUP,User-Name=USER_ID,NAS-IP-Address=172.16.1.139,NAS-Portname=tty1,Caller-Id=192.168.1.6,Acct-Flags=stop,service=shell,elapsed_time=1,task_id=134,
    Jul 13 22:08:35 10.10.10.10 CisACS_04_TACACSAcc 1ibkojwaq 1 0 Group-Name=USER_GROUP,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,NAS-Portname=tty1,Caller-Id=192.168.1.6,Acct-Flags=stop,service=shell,elapsed_time=121,task_id=196,
    *** much faster switchover the other way (one failed attempt, failover in < 1min):
    Jul 13 22:09:03 10.10.10.10 CisACS_02_FailedAuth 1q39b9oar 1 0 Message-Type=Authen failed,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Authen-Failure-Code=External DB is not operational,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,
    Jul 13 22:09:11 10.10.10.10 CisACS_01_PassedAuth 1sb62bwas 1 0 User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,Filter Information=Access Filter Deny_RZ-SAN from USER_GROUP did not fail any criteria. This is sufficient to satisfy an 'Any Selected' SPC NAR config.,
    Jul 13 22:09:17 10.10.10.10 CisACS_01_PassedAuth 1tz3mmkat 1 0 User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,Filter Information=Access Filter Deny_RZ-SAN from USER_GROUP did not fail any criteria. This is sufficient to satisfy an 'Any Selected' SPC NAR config.,
    Jul 13 22:09:23 10.10.10.10 CisACS_01_PassedAuth 1vn16x8au 1 0 User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Caller-ID=192.168.1.6,NAS-Port=tty1,Group-Name=USER_GROUP,Filter Information=Access Filter Deny_RZ-SAN from USER_GROUP did not fail any criteria. This is sufficient to satisfy an 'Any Selected' SPC NAR config.,
    Jul 13 22:09:42 10.10.10.10 CisACS_01_PassedAuth 1vqtscav 1 0 User-Name=USER_ID,NAS-IP-Address=172.16.1.138,Caller-ID=192.168.1.6,NAS-Port=tty2,Group-Name=USER_GROUP,Filter Information=Access Filter Deny_RZ-SAN from USER_GROUP did not fail any criteria. This is sufficient to satisfy an 'Any Selected' SPC NAR config.,
    Jul 13 22:09:42 10.10.10.10 CisACS_04_TACACSAcc 1vqtscaw 1 0 Group-Name=USER_GROUP,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,NAS-Portname=tty2,Caller-Id=192.168.1.6,Acct-Flags=start,service=shell,task_id=3782,
    Jul 13 22:10:21 10.10.10.10 CisACS_04_TACACSAcc cpazpoax 1 0 Group-Name=USER_GROUP,User-Name=USER_ID,NAS-IP-Address=172.16.1.138,NAS-Portname=tty2,Caller-Id=192.168.1.6,Acct-Flags=stop,service=shell,elapsed_time=39,task_id=3782,
    CSWinAgent_1 (10.11.11.16):
    *** service started manually:
    CSWinAgent 07/13/2010 21:47:14 A 0528 14340 0x0 Logging mode: LOW
    CSWinAgent 07/13/2010 21:47:14 A 0228 14340 0x0 CSWinAgent server starting ==============================
    CSWinAgent 07/13/2010 21:47:14 A 0233 14340 0x0 Running as console application.
    CSWinAgent 07/13/2010 21:47:14 A 0059 15332 0x0 Will listen on port 2005
    CSWinAgent 07/13/2010 21:47:14 A 0064 15332 0x0 Permitted CSWinAgent Clients: *.*.*.*
    CSWinAgent 07/13/2010 21:47:14 A 0116 15332 0x0 NTLIB: Library behaviour mode 2
    CSWinAgent 07/13/2010 21:47:14 A 0136 15332 0x0 NTLIB: Initialising locally
    CSWinAgent 07/13/2010 21:47:14 A 0139 15332 0x0 NTLIB: The local computer name is CSWinAgent_1
    CSWinAgent 07/13/2010 21:47:14 A 0171 15332 0x0 NTLIB: The insist on domain is disabled
    CSWinAgent 07/13/2010 21:47:14 A 0281 15332 0x0 NTLIB: We are NOT a domain controller
    CSWinAgent 07/13/2010 21:47:14 A 0423 15332 0x0 NTLIB: We are NOT a member of a domain => we cannot authenticate accounts on other trusted domains
    CSWinAgent 07/13/2010 21:47:14 A 0112 15332 0x0 Listener activated
    *** first incoming connection:
    CSWinAgent 07/13/2010 22:02:53 A 0140 15332 0x0 Client connecting from 10.10.10.10:2732
    CSWinAgent 07/13/2010 22:02:53 A 0390 15480 0x0 RPC: NT_MSCHAPAuthenticateUser received
    CSWinAgent 07/13/2010 22:02:53 A 1807 15480 0x0 NTLIB: Got WorkStation ACS
    CSWinAgent 07/13/2010 22:02:53 A 1808 15480 0x0 NTLIB: Attempting Windows authentication for user USER_ID
    CSWinAgent 07/13/2010 22:02:53 A 1866 15480 0x0 NTLIB: Windows authentication SUCCESSFUL (by CSWinAgent_1)
    CSWinAgent 07/13/2010 22:02:53 A 1947 15480 0x0 NTLIB: Domain name  in MSCHAPAuthenticateUser is  \LOCAL
    CSWinAgent 07/13/2010 22:02:53 A 1952 15480 0x0 NTLIB: Group Mapping Flag in MSCHAPAuthenticateUser is  enabled
    CSWinAgent 07/13/2010 22:02:53 A 1968 15480 0x0 NTLIB: Group Map Count in MSCHAPAuthenticateUser is  -1
    CSWinAgent 07/13/2010 22:02:53 A 0190 15480 0x0 NTLIB: User has 10 groups
    CSWinAgent 07/13/2010 22:02:53 A 0431 15480 0x0 RPC: NT_MSCHAPAuthenticateUser groups: None,LAN_Admins,Users,Administrators
    CSWinAgent 07/13/2010 22:02:53 A 0436 15480 0x0 RPC: NT_MSCHAPAuthenticateUser Domain Name is: CSWinAgent_1
    CSWinAgent 07/13/2010 22:02:53 A 0452 15480 0x0 RPC: Success
    CSWinAgent 07/13/2010 22:02:53 A 0465 15480 0x0 RPC: NT_MSCHAPAuthenticateUser reply sent
    *** second authentication:
    CSWinAgent 07/13/2010 22:04:20 A 0390 15480 0x0 RPC: NT_MSCHAPAuthenticateUser received
    CSWinAgent 07/13/2010 22:04:20 A 1807 15480 0x0 NTLIB: Got WorkStation ACS
    CSWinAgent 07/13/2010 22:04:20 A 1808 15480 0x0 NTLIB: Attempting Windows authentication for user USER_ID
    CSWinAgent 07/13/2010 22:04:20 A 1866 15480 0x0 NTLIB: Windows authentication SUCCESSFUL (by CSWinAgent_1)
    CSWinAgent 07/13/2010 22:04:20 A 1947 15480 0x0 NTLIB: Domain name  in MSCHAPAuthenticateUser is  \LOCAL
    CSWinAgent 07/13/2010 22:04:20 A 1952 15480 0x0 NTLIB: Group Mapping Flag in MSCHAPAuthenticateUser is  enabled
    CSWinAgent 07/13/2010 22:04:20 A 1968 15480 0x0 NTLIB: Group Map Count in MSCHAPAuthenticateUser is  -1
    CSWinAgent 07/13/2010 22:04:20 A 0190 15480 0x0 NTLIB: User has 10 groups
    CSWinAgent 07/13/2010 22:04:20 A 0431 15480 0x0 RPC: NT_MSCHAPAuthenticateUser groups: None,LAN_Admins,Users,Administrators
    CSWinAgent 07/13/2010 22:04:20 A 0436 15480 0x0 RPC: NT_MSCHAPAuthenticateUser Domain Name is: CSWinAgent_1
    CSWinAgent 07/13/2010 22:04:20 A 0452 15480 0x0 RPC: Success
    CSWinAgent 07/13/2010 22:04:20 A 0465 15480 0x0 RPC: NT_MSCHAPAuthenticateUser reply sent
    *** service stopped manually:
    CSWinAgent 07/13/2010 22:04:47 A 0046 14340 0x0 Service stopping
    CSWinAgent 07/13/2010 22:04:47 A 0049 14340 0x0 Shutting down NT library
    CSWinAgent 07/13/2010 22:04:47 A 0192 14340 0x0 NTLIB: Finalising locally
    CSWinAgent 07/13/2010 22:04:47 A 0053 14340 0x0 Shutting down EndPoint library
    CSWinAgent 07/13/2010 22:04:47 A 0609 15480 0x0 Client disconnected, thread 15480 terminating
    CSWinAgent 07/13/2010 22:04:47 A 0153 15332 0x0 Listener terminating
    CSWinAgent_2 (10.10.10.16):
    *** manual shutdown:
    CSWinAgent 07/13/2010 21:52:37 A 0046 1388 0x0 Service stopping
    CSWinAgent 07/13/2010 21:52:37 A 0049 1388 0x0 Shutting down NT library
    CSWinAgent 07/13/2010 21:52:37 A 0192 1388 0x0 NTLIB: Finalising locally
    CSWinAgent 07/13/2010 21:52:37 A 0053 1388 0x0 Shutting down EndPoint library
    CSWinAgent 07/13/2010 21:52:37 A 0609 3676 0x0 Client disconnected, thread 3676 terminating
    CSWinAgent 07/13/2010 21:52:37 A 0609 0340 0x0 Client disconnected, thread 340 terminating
    CSWinAgent 07/13/2010 21:52:37 A 0609 2900 0x0 Client disconnected, thread 2900 terminating
    CSWinAgent 07/13/2010 21:52:37 A 0609 3404 0x0 Client disconnected, thread 3404 terminating
    CSWinAgent 07/13/2010 21:52:37 A 0153 1944 0x0 Listener terminating
    CSWinAgent 07/13/2010 21:52:37 A 0609 2072 0x0 Client disconnected, thread 2072 terminating
    CSWinAgent 07/13/2010 21:52:37 A 0609 3576 0x0 Client disconnected, thread 3576 terminating
    *** service started manually:
    CSWinAgent 07/13/2010 22:09:48 A 0528 3504 0x0 Logging mode: LOW
    CSWinAgent 07/13/2010 22:09:48 A 0228 3504 0x0 CSWinAgent server starting ==============================
    CSWinAgent 07/13/2010 22:09:48 A 0233 3504 0x0 Running as console application.
    CSWinAgent 07/13/2010 22:09:48 A 0059 3480 0x0 Will listen on port 2005
    CSWinAgent 07/13/2010 22:09:48 A 0064 3480 0x0 Permitted CSWinAgent Clients: *.*.*.*
    CSWinAgent 07/13/2010 22:09:48 A 0116 3480 0x0 NTLIB: Library behaviour mode 2
    CSWinAgent 07/13/2010 22:09:48 A 0136 3480 0x0 NTLIB: Initialising locally
    CSWinAgent 07/13/2010 22:09:48 A 0139 3480 0x0 NTLIB: The local computer name is CSWinAgent_2
    CSWinAgent 07/13/2010 22:09:48 A 0171 3480 0x0 NTLIB: The insist on domain is disabled
    CSWinAgent 07/13/2010 22:09:48 A 0281 3480 0x0 NTLIB: We are NOT a domain controller
    CSWinAgent 07/13/2010 22:09:48 A 0423 3480 0x0 NTLIB: We are NOT a member of a domain => we cannot authenticate accounts on other trusted domains
    CSWinAgent 07/13/2010 22:09:48 A 0112 3480 0x0 Listener activated
    *** first authentication:
    CSWinAgent 07/13/2010 22:10:42 A 0140 3480 0x0 Client connecting from 10.10.10.10:2782
    CSWinAgent 07/13/2010 22:10:43 A 0390 2800 0x0 RPC: NT_MSCHAPAuthenticateUser received
    CSWinAgent 07/13/2010 22:10:43 A 1807 2800 0x0 NTLIB: Got WorkStation ACS
    CSWinAgent 07/13/2010 22:10:43 A 1808 2800 0x0 NTLIB: Attempting Windows authentication for user USER_ID
    CSWinAgent 07/13/2010 22:10:43 A 1866 2800 0x0 NTLIB: Windows authentication SUCCESSFUL (by CSWinAgent_2)
    CSWinAgent 07/13/2010 22:10:43 A 1947 2800 0x0 NTLIB: Domain name  in MSCHAPAuthenticateUser is  \LOCAL
    CSWinAgent 07/13/2010 22:10:43 A 1952 2800 0x0 NTLIB: Group Mapping Flag in MSCHAPAuthenticateUser is  enabled
    CSWinAgent 07/13/2010 22:10:43 A 1968 2800 0x0 NTLIB: Group Map Count in MSCHAPAuthenticateUser is  -1
    CSWinAgent 07/13/2010 22:10:43 A 0190 2800 0x0 NTLIB: User has 10 groups
    CSWinAgent 07/13/2010 22:10:43 A 0431 2800 0x0 RPC: NT_MSCHAPAuthenticateUser groups: None,LAN_Admins,Administrators,Users
    CSWinAgent 07/13/2010 22:10:43 A 0436 2800 0x0 RPC: NT_MSCHAPAuthenticateUser Domain Name is: CSWinAgent_2
    CSWinAgent 07/13/2010 22:10:43 A 0452 2800 0x0 RPC: Success
    CSWinAgent 07/13/2010 22:10:43 A 0465 2800 0x0 RPC: NT_MSCHAPAuthenticateUser reply sent
    *** some more logins:
    CSWinAgent 07/13/2010 22:10:49 A 0140 3480 0x0 Client connecting from 10.10.10.10:2784
    CSWinAgent 07/13/2010 22:10:49 A 0390 2296 0x0 RPC: NT_MSCHAPAuthenticateUser received
    CSWinAgent 07/13/2010 22:10:49 A 1807 2296 0x0 NTLIB: Got WorkStation ACS
    CSWinAgent 07/13/2010 22:10:49 A 1808 2296 0x0 NTLIB: Attempting Windows authentication for user USER_ID
    CSWinAgent 07/13/2010 22:10:49 A 1866 2296 0x0 NTLIB: Windows authentication SUCCESSFUL (by CSWinAgent_2)
    CSWinAgent 07/13/2010 22:10:49 A 1947 2296 0x0 NTLIB: Domain name  in MSCHAPAuthenticateUser is  \LOCAL
    CSWinAgent 07/13/2010 22:10:49 A 1952 2296 0x0 NTLIB: Group Mapping Flag in MSCHAPAuthenticateUser is  enabled
    CSWinAgent 07/13/2010 22:10:49 A 1968 2296 0x0 NTLIB: Group Map Count in MSCHAPAuthenticateUser is  -1
    CSWinAgent 07/13/2010 22:10:49 A 0190 2296 0x0 NTLIB: User has 10 groups
    CSWinAgent 07/13/2010 22:10:49 A 0431 2296 0x0 RPC: NT_MSCHAPAuthenticateUser groups: None,LAN_Admins,Administrators,Users
    CSWinAgent 07/13/2010 22:10:49 A 0436 2296 0x0 RPC: NT_MSCHAPAuthenticateUser Domain Name is: CSWinAgent_2
    CSWinAgent 07/13/2010 22:10:49 A 0452 2296 0x0 RPC: Success
    CSWinAgent 07/13/2010 22:10:49 A 0465 2296 0x0 RPC: NT_MSCHAPAuthenticateUser reply sent
    CSWinAgent 07/13/2010 22:10:52 A 0140 3480 0x0 Client connecting from 10.10.10.10:2786
    CSWinAgent 07/13/2010 22:10:52 A 0390 1768 0x0 RPC: NT_MSCHAPAuthenticateUser received
    CSWinAgent 07/13/2010 22:10:52 A 1807 1768 0x0 NTLIB: Got WorkStation ACS
    CSWinAgent 07/13/2010 22:10:52 A 1808 1768 0x0 NTLIB: Attempting Windows authentication for user USER_ID
    CSWinAgent 07/13/2010 22:10:52 A 1866 1768 0x0 NTLIB: Windows authentication SUCCESSFUL (by CSWinAgent_2)
    CSWinAgent 07/13/2010 22:10:52 A 1947 1768 0x0 NTLIB: Domain name  in MSCHAPAuthenticateUser is  \LOCAL
    CSWinAgent 07/13/2010 22:10:52 A 1952 1768 0x0 NTLIB: Group Mapping Flag in MSCHAPAuthenticateUser is  enabled
    CSWinAgent 07/13/2010 22:10:52 A 1968 1768 0x0 NTLIB: Group Map Count in MSCHAPAuthenticateUser is  -1
    CSWinAgent 07/13/2010 22:10:52 A 0190 1768 0x0 NTLIB: User has 10 groups
    CSWinAgent 07/13/2010 22:10:52 A 0431 1768 0x0 RPC: NT_MSCHAPAuthenticateUser groups: None,LAN_Admins,Administrators,Users
    CSWinAgent 07/13/2010 22:10:52 A 0436 1768 0x0 RPC: NT_MSCHAPAuthenticateUser Domain Name is: CSWinAgent_2
    CSWinAgent 07/13/2010 22:10:52 A 0452 1768 0x0 RPC: Success
    CSWinAgent 07/13/2010 22:10:52 A 0465 1768 0x0 RPC: NT_MSCHAPAuthenticateUser reply sent

  • ACS appliance and remote agent testing

    Having problems with integrating ACS appliance with Active Directory. Have installed the remote agent on a member server and from the ACS appliance can enumerate the Active Directory groups correctly so there is at least some communication happening.
    Looking at the remote agent logs whenever a request for the AD groups comes through you see corresponding log entrys. When a user tries to authenticate though there are no logs coming through to the remote agent. So maybe it is not being sent to remote agent?
    In the failed authentications log on the ACS the error is unknown user, it does show the correct username + domain as the person trying to authenticate.
    The Windows server is setup for unknown user policy.
    ACS version is 4.1.1.23, Remote Agent is latest version available.
    Any ideas or things to check?

    Hi,
    As per your last line, It seems that ACS and RA ver are not same. Please note that ACS appliance and RA software ver has to be same else it won't work.
    Regards,
    ~JG

Maybe you are looking for