WAAS conection limit alarm

Hi,
I have a waas solution implemented, where the both (Datacenter and Edge) are in inline mode. The WAE in Datacenter side is viewing all connections from the others sites of the WAN where there is not a WAE in there, so that connections are in PT becouse "Not Peer".
These days we started to see a minor alarm: "1 max_conn_overload sysmon accl=TFO". We don't see this alarm from the Edge WAE, only from Datacenter WAE.
Could be that DC WAE takes in account the PT connections? if the answer is yes, Can this overload make that the WAE stop the optimization when new connections arrive until the number of connections go down?
Thanks in advanced!!!
Celeste
These days we started to see a minor alarm: "1 max_conn_overload sysmon accl=TFO". We don't see this alarm from the Edge WAE, only from Datacenter WAE.
Could be that DC WAE take in account the PT connections? if the answer is yes, Can this overload makes that the WAE stops the optimization when new connections arrive until the number of connections goes down?

Thanks for the update, can you check one more thing on your WAE-Tronador box? can you do the following command?
find-pattern match "Routing Loop" syslog.txt
We are looking for the following enteries similar to "opt_syn_rcv: Routing Loop
detected - Packet has our own devid. Packet dropped."
Also, do "sh stat auto" and look for the entry:
Auto discovery Miscellaneous
SYNs found with our device id: XX
If you see that counter incrementing, you may be hitting DDTS: CSCsx68058 "Routing loops at the core can cause TFO overload on the WAE " If this is the case, then you need to inspect you interception at the core to ensure that you are not re-intercepting traffic egressing the WAE on the router.
Let me know if this is the case or we can keep searching.
Thanks,
Dan

Similar Messages

  • Custom limit&alarm on iSPC Chart

    Hi everyone,
    I'm trying to set up a custom limit inside an iSPCChart.
    If I look the iSPCChart display template configuration, under "Upper Chart Spec. Limits" Template Catagory I find:
    Upper Spec. Limit of Upper Chart User
    Target of Upper Chart User
    Lower Spec. Limit of Upper Chart User
    Show Upper User Specification Limits
    Show Upper User Target
    In your opinion, could I use those properties to reach my aim?
    If the value of my custom limit is a variable, could I pass it through scripting?
    Once I set up the limit into dispaly template, how can I activate alarm on it's violation? It's not present in "Alarms" Template Category...
    Another option in my mind it is to tricky use the Control Limits configuration as a custom limit (probably my process will not need to be scouted on control limits too). Following this solution, could I rename the legend object somehow displaying a meaningful label ?  
    best regards

    If I'm not mistaken, when the User limits were added to the chart it was more for 'what if' type views for interacting with the chart (drawing and visualizing up to the 3 user spec lines), and alarming was not part of this because there is no 'SPC Rule' (WECO or Nelson) that would be applicable to these unofficial spec limits.
    You could script the values (setUpperUserXXXX would be the method pattern for the chart object), and provide the user with a 'what if my specs were x,y,z' preview option.
    Using the Control limits would provide you with alarming needs, and since in most cases you would try to 'control' your process in a tighter bandrange within your 'specification' bandrange, but the legend characters are not editable.  A custom legend would be another option if you chose to go this route.

  • NCS Block/Limit Alarms?

    I am stumped on this one.  Our campus is switching over to NCS from WCS.  The system is great overall but I cannot find a method to reduce alarms.  If I have an AP I use for testing, and then disconnect it - I will get alerts every 30 minutes pretty much no matter what I do short of deleting the AP.  I don't want to reduce "disassociated" AP alarm to the point that I don't get critical alarms.  Also I have tried placing this "test" AP in a maintenance state, but I still seem to get alarms on it...any other ideas?  Preferably I would like to just reduce alarm time from 30 minutes to a longer time period, or block alarms totally on certain items. 

    I see two place to configure alarms
    Monitor-->Alarms
    Can Aknowledge, Assign, etc.  Can enable or disable email alerts
    Administration-->Settings-->Severity Configuration.  Can change severity level for various alarms.
    I have not been able to find anywhere to change re-occurence time.  I would like to get the alerts that I am getting - but maybe every say 120 minutes instead of every 30 minutes...
    Thanks
    ~Tom

  • WAAS Connection Limit

    Hi,
    Will the WAE or CM show an error message if the connection limit is reached on a WAE?
    Thanks,
    Mike

    When the WAE/WAVE device reached max connection limit - any new connections will go into pass through due to overload
    Existing connections will be still be optimized.
    Thanks
    Eric
    If this answers your questions please mark as answered with a 5.

  • Error Code 8450 when download app use paypal for unipay debit card in China

    I tried both desktop or smartphone when i buy speed limit alarm for 0.75$, there is a valid preproved payment  at my paypal account, of course my us account deposite is 0 ,for  i use a debit card for payment. 
    i have learned that paypal said he will automatically exchange RMB to US$, so i think this does not a matter.
    what is the truth i met? I am a computer engineer, in China, if I can't successful buy and download a rim app, I don't think most of others can do . 
    if rim can't move the barrier for his custom  in sales, how can rim get to live? must i hop betwen rim and paypal to settle this problem by myself?  caution this bug hurt your bussiness.
    i'm a little sad that i can only search one related topic about the error code 8450, but that does no effect. and i tried find a help phone in china for support but faild.
    RIM is downing? I don't hope so, I love my 8310 very much!

    Do you have enough funds in your bank account?
    otherwise iTunes sometimes black lists card if there are too many fradulent purchases
    Reason why they might black list a card is possibly you call in for alot of fradulent purchases
    One more reason can be because iTunes does actually limit the amount you can change payment methods
    Call AppleCare Phone support and have your call directed to iTunes Store
    1-800-275-2273

  • MII implementation of WECo rule. Zone A

    Dear Forum,
    I would like to configure the SPC chart in MII to have an alarm when a data point falls beyond 3 standard deviations from the center line. The zone A alarm is activated when the data point falls in zone A or beyond (this is between 2 and 3 sd, and beyond) if i understand correctly.
    Is there any way to have only the points beyond zone A or am i wrong in the understanding of the rule?
    I'm using MII 11.5
    Thanks in advance for the help,
    Jose Luis

    Hi Jose,
    I not an SPC expert by far, but from what I seen, it looks like the areas of standard deviation fall between the Control Limits.  Perhaps it would be possible to use the Control Limit Alarm, which would alarm a single point outside of the Control Limits.
    I know that Zone A is the region between two and three standard deviations from the centerline, so I don't see that this alarm would work for points outside of 3 standard deviations.
    Kind Regards,
    Diana Hoppe

  • Why do input tags stop working when I add more tags to my project ?

    I'm having a problem with tags, when I add more input tags to my project the rest of the tags stop responding, that is when I monitor them with the tag monitor I get a low limit error, if I delete the new tags in the project the rest of the tags start working ok, the whole project has 804 tags, and I'm using a Pentium 4 2.8GHz server, 256 Mb RAM and Windows 2000 Advanced Server, Any idea of what could be happening ?

    Hello, I'm attaching the SCF File, the new tags that we created when the problem started are "VoltajeBateriaPozo11" and "VoltajeLineaPozo11" through "VoltajeBateriaPozo15" and "VoltajeLineaPozo15" (new set of tags)
    When this set of new tags are included in the SCF file the tags "VoltajeBateriaPozo1" and "VoltajeLineaPozo1" through "VoltajeBateriaPozo15" and "VoltajeLineaPozo15"
    don't show the correct value when we monitor them (We get the low limit alarm), the rest of the tags work properly.
    When we delete the new set of tags all the tags work properly (including "VoltajeBateriaPozo1" and "VoltajeLineaPozo1" through "VoltajeBateriaPozo10" and "VoltajeLineaPozo10").
    The OPC server we are using is the National Instruments OPC Lo
    okOut Driver Version 4.5, the alarms are not communication alarms.
    Thank you for your help.
    Attachments:
    TurbioTags.scf ‏282 KB

  • P Chart With Variable UCL

    Hello,
    I am trying to use an iSPCChart in P mode.  My sample size varies per point and I am specifying a Sample Size Column on the display template's Data Mapping tab. I have the box checked to Calculate Control Limits on the Limits tab.
    My problem is that the upper control limit does not show up on the chart even though I have Show Control Limits checked on the Upper Chart tab.  The lower control limit does show up.
    Is there a way to get the UCL to show up on the P chart when it is calculated and it varies due to varying sample sizes?
    Thanks,
    Mike

    Hi Udayan,
    It appears that the UCL is being calculated.  If I do a right-click on the applet and then Data -> SPC Results Detail, each position has a UCL listed.  They range from 0.02 to 0.05 (depending on the sample size).
    In the summary section at the top of the SPC Details, however, it says NA for UpperChartUCL. I think this is because I did not specify a static UCL in the template.
    Also, on my chart one of my plotted points is red indicating that the upper control limit alarm point has been exceeded.  The control limit alarm is the only alarm I have turned on.
    So, I think it is calculating the UCL properly and that it is using it properly in terms of assessing the alarm conditions but, for some reason, it is not drawing the UCL on the chart.
    Thanks for your help.
    Mike

  • Brewery tank controls

    Hello all -
    I'm looking to develop a system for controlling the Fermentation tanks
    in our brewery using LabView controls.  We currently use the standard
    tempermental fuzzy logic PID microcontrolers (Partlow, Watlow, etc).  I
    believe these are overly expensive for the functionality they provide,
    and being a both a professional Brewer and a LabView/systems guy I am
    always seeking better ways to control the process.  Programatically, I
    realize all the flexible advantages LabView would have for our system,
    however I'm evaluating the feasibility ( on a cost basis) of replacing
    these with a custom LabView controlled system.
    Our current process:  A type K thermocouple monitors the tank
    temperature via the fuzzy logic controller.  The controller's alarm
    relay (rated 5 amps at 110 VAC) responds based on a setpoint and will
    either send coolant thru the jacketed tank or not. The controller alarm
    relay activates a seperate solid state relay (20 mA) which then sends
    an electrical signal to a circulating pump (single phase, 115 Volt,
    ranging 0.5-2.0 amps) and a solenoid valve (120 Volt coil) with their
    own power sources. 
    We currently use this system as an on/off controller.  The tanks are
    either cooling or not - and control beyond that is manual.  I realize
    that soaking, ramping, and other functions can be set with these
    controllers but not only do we have numerous controller brands with
    different parameters, but the programming is beyond the scope of many
    of the people that operate the system.  I'm looking to build in user
    friendly functionality and operate all the tank controls from one
    central computer hub.
    So the question is, how do I replace the controllers and wire for
    LabView control of the motors and solenoids?  Is the solution to just
    run wires to a big Data Acquisition board connected to a central computer? Or
    is building a wireless network of tanks feasible? (My budget will be
    relatively small)  We've got 14 tanks to control spaced evenly over
    about 4,000 sq. ft. Any idea's, experience, hardware suggestions, etc. - I'd love
    to hear.  Thanks in advance for all your help!
    - John Rehm
    Brewer in Chief, Philadelphia Brewing Co.
    LabView Instructor, La Salle University
    From McMaster Carr supply (www.mcmastercarr.com):
    Autotuning P-I-D Temperature Controllers
     1/16 DIN
       These
    autotuning controllers with fuzzy logic calculate the optimal P-I-D
    (Proportional-Integral-Derivative) parameters for a particular process
    and store them in memory for future use. Controllers accept input from
    RTDs and thermocouple types J (-58° to +1832°  F/-50° to +1000°  C), K
    (-58° to +2498°  F/-50° to +1370°  C), and T (-454° to
    +752°  F/-270° to +400°  C). Units are easy to program using menu and
    keypad. Each has selectable auto/manual control modes, two limit alarm
    relays with eight programmable modes, and ramp/soak programming ("ramp"
    for length of time to reach a temperature and "soak" for length of time
    a temperature is maintained).
       Controllers are ° F/° C selectable,
    and dual LED displays show present temperature and setpoint
    simultaneously. Top LED is red, and bottom LED is green. Units accept
    probes with bare lead wires (probes sold separately).
    Operate on 90 to 264 VAC. All include screw terminal connections and
    mounting brackets. Accuracy is ±0.36°  F (±0.2°  C) for RTDs and
    ±1.8°  F (±1°  C) for thermocouples. CE approved.
        1/16 DIN size units have one control and two alarm relays with SPST contacts that are wired normally open and rated 5 amps at 110 VAC. Top LED is  3/8" high, and bottom LED is  5/16" high.
        1/4 DIN size units have two control and two alarm relays with SPST contacts that are wired normally open and rated 5 amps at 110 VAC. Top LED is  9/16" high, and bottom LED is  3/8" high.

    Hi John.  A couple of suggestions:
    1) If there is any way to remotely program your existing controllers, building your system on them may
    have several advantages.  Lets you use your existing hardware and wiring, reduces new stuff to buy,
    and gives you a fall-back position if problems crop up with the master controller.  Also can be
    implemented in stages, a few tanks at a time.
    2) Replacing your existing controllers with remotely programmable ones still gives you the other advantages
    of the architecture above, just you have to buy new controllers.
    3) Fieldpoint hardware is certainly capable of doing what you want, and gives you independence from
    a PC, i.e. you can download your process parameters to the Fieldpoint controller and disconnect the
    PC, or leave it running as a monitor.  Gives you the reliability of an industrial controller with the option
    of a PC GUI.  You could run all 14 tanks with one controller.
    For a 4000 ft^2 facility, I wouldn't expect wireless to be worth the trouble unless there are other
    considerations like mobile equipment.
    I am in Jenkintown.  I'd be happy to trade tips for a tour.  Are you involved with the ISBT program?
    Matt

  • I Just Can't Stop!

    My vi has a stop button on the front panel but only the "abort
    execution"button
    stops the vi completely.This vi writes/reads through the parallel port to a
    LTC1298 A/D chip.I use Labview 6i on Windows 98se.
    The vi diagram consists of a 2 frame sequence structure inside of a While
    loop.Inside frame 0 there is a For loop which contains an Outport sub vi.
    the For loop iterates 12 times to initialize the chip.
    In frame 1 there is another For loop which has an Outport and an Inport
    sub vi.This For loop iterates 24 times to read 12 bits from the A/D
    chip.Also
    inside frame 1 and beside the For loop are various functions for displaying
    the
    12 bits,their numerical value,high/low limit alarm,and a Wait timer.A wire
    from
    this area connects to a Waveform Chart
    terminal located just outside the
    While loop.Hitting the Stop button on the front panel stops the Waveform
    Chart but
    the reading and the writing continues.
    I've tried different mechanical settings for the Stop button,default T/F,
    and T/F for the Conditional terminal in the While loop. The Stop terminal is
    currently
    inside Frame 1,but has been almost everywhere else.How to stop?

    Nothing is going to terminate a for loop (except the "Abort") until all of it's iterations complete. You've got two of them inside of a sequence which also will not terminate until it's completed. At the very least, you'll need to replace the for loops with while loops that can terminate early. You should also put the stop terminal outside of the sequence structure. In fact, I'm one of those persons that say a sequence structure should never be used. The LabVIEW state machine will give you more flexibility. There's plenty of examples to be found - even one that ships with LabVIEW.

  • Redundant Tasks in VI?

    Good Morn everybody
    I'm thinking about bringing in the same task twice in my VI but in seperate WLoops.  Potential Problems?  Is this possible?
    Thank you,
    BLW

    I tried it and got nothing.  The data port of my read channel in the top while loop and the "run protocol" case structure is sending a big fat zero.  Please take a look at my code and make suggestions...  maybe I need to scrap and start over but I can't think of another way to write this???
    Thank you,
    BLW
    Attachments:
    PID Testing.vi ‏444 KB
    gas limit alarm.vi ‏15 KB
    State Machine States Enum.ctl ‏6 KB

  • WAAS alarm simulation

    Hi team,
    one theoretical question:
    is there any way how to simulate (generate) the following WAAS alarms in the lab enviroments, please ?
    •             Disk early-prediction failure
    •             Disk failure
    •             Cache disk full
    •             Cache disk overloaded
    •             TFO overloaded (TCP connection limit reached)
    •             Alarm overload state
    I believe that traffic generator will not help here as it cannot generate enough TCP sessions.
    Many thanks!
    Regards,
    Stan

    Hi Stan,
    For the Disk Failure alarm, you can simply remove a disk from your appliance and it should trigger it.
    The rest of them will be difficult to trigger at will.
    For the TFO overloaded, a simple script that spawns telnet sessions through the WAAS should allow you to reach this state. To see how many you would need, you can have a look at the "sh tfo detail" output.
    Hope this helps.
    Regards,
    Nicolas

  • WAAS WAE Alarm 'mstore_key_retrieval'

    Hello,
    I am supporting an environment that has 30+ remote WAEs deployed with a CM at the HQ.
    All remote WAE's Versions = Cisco Wide Area Application Services (universal-k9) Software Release 4.2.3b (build b4 Oct  4 2010)
    HQ's CM version = Cisco Wide Area Application Services (universal-k9) Software Release 4.4.3 (build b4 Aug 22 2011)
    On 4 of these WAEs, I currently am receiving encryption key alarms:
    WAE#show alarms detail support
    Critical Alarms:
            Alarm ID                 Module/Submodule               Instance
       1 mstore_key_retrieval      cms                          ssl_mstore_key          
         Apr 11 18:36:16.026 CDT, Processing Error Alarm, #000002, 3000:700008
         Unable to generate and/or retrieve SSL managed store encryption key from the Key Manager
         /alm/crit/cms/mstore_key_retrieval_failure:
             CMS/Management agent failed to generate and/or retrieve SSL managed store encryption key from Key Manager.
         Explanation:
             This alarm indicates one of following issues: Central
             Manager device(s) is not reachable.  Secure store on
             Central Manager is initialized but not open.  Key Manager
             process on Central Manager device is not running or failing
             to respond.  Key Manager is unable to process key
             generation or retrieval request.   If this issue is
             present, the WAE device will not be able to process  a
             configuration update received from the Central Manager if
             it  contains SSL certificate/key information.
         Action:
             Check if Central Manager device is reachable (TCP
             connections from the WAE to the Central Manager on port
             443) Check following log files for additional information
             about the error: /local1/errorlog/kc.log on WAE
             /local1/errorlog/km/km.log on CM
       2 mstore_key_failure        sslao                        mstore_key_failure      
         Apr 11 18:39:07.518 CDT, Processing Error Alarm, #000006, 26000:26002
         Failed to open SSL store due to failure in getting key from Central Manager.
         /alm/crit/sslao/mstore_key_failure:
             SSL managed secure store key retrieval failure.
         Explanation:
             The SSL accelerator is unable to get the SSL secure store
             key from the Central Manager.
         Action:
             Check the connection with the Central Manager.
    The explanations and actions match the alarm book , but in addition to that, in the Cisco WAAS Monitoring Guide, it also states:
    Alarm 700008 (mstore_key_retrieval_failure) CMS/Management agent failed to generate and/or retrieve SSL managed store encryption key from Key Manager.
    Severity: Critical
    Category: Processing
    Description: This alarm indicates one of following issues:
    –The WAAS Central Manager device is not reachable
    –Secure store on WAAS Central Manager is initialized but not open
    –The Key Manager process on the WAAS Central Manager device is not running or failing to respond
    –Key Manager cannot process key generation or retrieval request. If this issue is present, the WAAS device cannot process a configuration update received from WAAS Central Manager if it contains SSL certificate and key pair information.
    Action: Check to see if the WAAS Central Manager device is reachable (TCP connections from the WAE to the WAAS Central Manager on port 443). Check the following log files for additional information about the error:
    –On WAE: /local1/errorlog/kc.log on WAE
    –On WAAS Central Manager: /local1/errorlog/km/km.log
    Action: Fix the clock on the device or the primary WAAS Central Manager.
    For a complete list of alarm conditions, see the Alarm Book located in the WAAS 4.2.1 Software Download area on Cisco.com.
    Using this information, I've checked the following:
    TCP 443 is reachable from the WAE to the CM (I can telnet from each WAE to the CM on TCP 443)
    Time is correct on the WAEs and CM ('show ntp status' and 'show clock' are consistent)
    Secure store on CM is open ('show cms secure-store' on the CM shows that the mode is in 'Open' state),
    Verified that the key manager process is running (Looking at the CM's KM log shows plenty of action that it's working for other WAEs)
    Here is some information I gathered from the WAEs' kc.log files and the CM's km.log (slightly scrubbed):
    From the WAEs' kc.log files:
    pool-1-thread-1] INFO  CommClientAbstractRPC - Send key retrieval request to CM 10.x.x.x for token d1b77e45-ce60-4332-a92d-3d3cb17d35cf
    pool-1-thread-1] WARN  CommClientAbstractRPC - Received error response from KM(20,No key found for token d1b77e45-ce60-4332-a92d-3d3cb17d35cf from device 17111)
    From the CM's km.log file:
    [pool-1-thread-4] INFO - retrieveKey request, token=d1b77e45-ce60-4332-a92d-3d3cb17d35cf from device WAE1/17111
    [pool-1-thread-4] INFO - Checking secure store open
    [pool-1-thread-4] INFO - Loading KEK from data server
    [pool-1-thread-4] INFO - ticket 17111 (1327767406332, 1327767392433, 13899, 10000)
    [pool-1-thread-4] WARN - No key found for token d1b77e45-ce60-4332-a92d-3d3cb17d35cf from device 17111
    *** Going through these logs, I've seen other devices have the same issue, and eventually a WAE records the following:
    [main] ERROR DeviceInfo - /state/node.dat (No such file or directory)
    java.io.FileNotFoundException: /state/node.dat (No such file or directory)
    at java.io.FileInputStream.open(Native Method)
    at java.io.FileInputStream.<init>(Unknown Source)
    at java.io.FileInputStream.<init>(Unknown Source)
    at com.cisco.waas.kc.DeviceInfo.retrieveNodeInfo(DeviceInfo.java:65)
    at com.cisco.waas.kc.DeviceInfo.<init>(DeviceInfo.java:47)
    at com.cisco.waas.kc.DeviceInfo.getInstance(DeviceInfo.java:37)
    at com.cisco.waas.kc.comm.CommClientAbstractRPC.retrieveKey(CommClientAbstractRPC.java:149)
    at com.cisco.waas.kc.RetrieveKeyCommand.execute(RetrieveKeyCommand.java:43)
    at com.cisco.waas.cli.CLICommand.execute(CLICommand.java:114)
    at com.cisco.waas.cli.AbstractCLI.process(AbstractCLI.java:28)
    at com.cisco.waas.kc.KeyClient.main(KeyClient.java:40)
    [main] ERROR DeviceInfo - /state/node.dat (No such file or directory)
    java.io.FileNotFoundException: /state/node.dat (No such file or directory)
    at java.io.FileInputStream.open(Native Method)
    at java.io.FileInputStream.<init>(Unknown Source)
    at java.io.FileInputStream.<init>(Unknown Source)
    at com.cisco.waas.kc.DeviceInfo.retrieveNodeInfo(DeviceInfo.java:65)
    at com.cisco.waas.kc.DeviceInfo.<init>(DeviceInfo.java:47)
    at com.cisco.waas.kc.DeviceInfo.getInstance(DeviceInfo.java:37)
    at com.cisco.waas.kc.comm.CommClientAbstractRPC.initKey(CommClientAbstractRPC.java:40)
    at com.cisco.waas.kc.InitKeyCommand.execute(InitKeyCommand.java:40)
    at com.cisco.waas.cli.CLICommand.execute(CLICommand.java:114)
    at com.cisco.waas.cli.AbstractCLI.process(AbstractCLI.java:28)
    at com.cisco.waas.kc.KeyClient.main(KeyClient.java:40)
    *** Followed with what appears to be a new SSL key being generated ***:
    [main] INFO  DeviceInfo - loaded device info, hash  H04Fer5il3b/9oanDZXx/7aBnIo=
    [pool-1-thread-1] DEBUG CMProber$ProbeWorker - Sending CM probe request to CM 10.x.x.x
    [pool-1-thread-1] DEBUG CMProber$ProbeWorker - CM 10.x.x.x returned :primary:4.4.3.0.4
    [pool-1-thread-1] DEBUG CMProber$ProbeWorker - Primary CM address 10.x.x.x version 4.4.3.0.4
    [main] DEBUG CommClientAbstractRPC - CM version 4.4.3
    [main] INFO  CommClientAbstractRPC - Send key initialization request to CM 10.x.x.x key type SSL
    [main] INFO  CommClientAbstractRPC - Received new token for generated key SSL/cbe3d6fc-875e-4b61-baeb-528c55cb3597
    [main] INFO  DeviceInfo - loaded device info, hash  H04Fer5il3b/9oanDZXx/7aBnIo=
    [pool-1-thread-1] INFO  CommClientAbstractRPC - Send key retrieval request to CM 10.0.65.234 for token cbe3d6fc-875e-4b61-baeb-528c55cb3597
    [main] INFO  CommClientAbstractRPC$1 - Successfully retrieved key from CM for token cbe3d6fc-875e-4b61-baeb-528c55cb3597
    *** And the CM records the following ***:
    [pool-1-thread-4] INFO - initKey request from device WAE2/30129 key type SSL
    [pool-1-thread-4] INFO - Checking secure store open
    [pool-1-thread-4] INFO - Loading KEK from data server
    [pool-1-thread-4] INFO - Return crypto of type : 0
    [pool-1-thread-4] INFO - Checking secure store open
    [pool-1-thread-4] INFO - Loading KEK from data server
    [pool-1-thread-4] INFO - Loading KEK from data server
    [pool-1-thread-4] INFO - Generated new key WAE2/SSL token cbe3d6fc-875e-4b61-baeb-528c55cb3597
    I'm wanting to know why this occurs on some boxes and not others, and what triggers the process for a WAE to stop repeatedly sending key retrieval requests with a token that the CM has repeatedly replies with the key not being found and performing an initial key request.
    Thanks!

    Hi all, I got into the same issue and looking at a solution I found a way to clear those alarms whithout re-registering the WAE/WAVE. Here it goes...
    WAE##sh accelerator
    Accelerator     Licensed        Config State    Operational State
    cifs            Yes             Enabled         Running
    epm             Yes             Enabled         Running
    http            Yes             Enabled         Running
    mapi            Yes             Enabled         Running
    nfs             Yes             Enabled         Running
    ssl             Yes             Enabled         Disabled  ---> your SSL AO is probably down due the issue
    video           No              Enabled         Shutdown
    WAE#sh alarms
    Critical Alarms:
            Alarm ID                 Module/Submodule               Instance
       1 mstore_key_retrieval      cms                          ssl_mstore_key
       2 mstore_key_failure        sslao                        mstore_key_failure
    Major Alarms:
    None
    Minor Alarms:
    None
    WAE#crypto pki managed-store initialize
    All certificate/private keys in SSL managed store will be deleted and optimized SSL traffic will be interrupted. Are you sure you want to continue(yes/no)? [no]:yes
    Restarting SSL accelerator. Done.
    After a couple of minutes alarms will be cleared and SSLAO will be back UP.
    WAE#sh accelerator
    Accelerator     Licensed        Config State    Operational State
    cifs            Yes             Enabled         Running
    epm             Yes             Enabled         Running
    http            Yes             Enabled         Running
    mapi            Yes             Enabled         Running
    nfs             Yes             Enabled         Running
    ssl             Yes             Enabled         Running
    video           No              Enabled         Shutdown
    WAE#sh alarms
    Critical Alarms:
    None
    Major Alarms:
    None
    Minor Alarms:
    None
    In case you have the issue in the Core WAE (where the cms secure-store is opened), you might need to initialize it.
    Regards,
    Fernando

  • How to delete the alarm "Certificate is near expiration" on multiple WAEs using WAAS CM

    Hi,
    We are getting "Certificate is near expiration" alarm on more than  200 WAEs . Instead of deleting the expired certificates manually from each device,
    how to delete this alarms/certificates on all the devices from WAAS CM ?
    Please advice..
    Regards,
    Ameen.

    Ameen,
    I believe there is script that you could use to address this issue on multiple devices at once.
    Please open a TAC case so that TAC Engineer would assist with this.
    For a single WAE, it is documented here.
    https://supportforums.cisco.com/thread/2010020
    Thanks
    Anil

  • How to eliminate the alarm "Client License Limit Exceeded" in Lookout 6.0.2?

    There are 18 Run Time Only Servers, with no clients, running the same application. Right after the installation of the Lookout 6.0.2 software this alarm didn't show up, but after some time it does in all the systems. It makes not too much sense to me because there are no clients at all, thus no client license was purchased and entered/registered.
    How to eliminate this 'false' alarm?
    Any help will be appreciated!

    The design is complex. Within the features, each system collects data in .csv format, and once a day moves a copy of the data collected to some place in the network. Also the systems print to file the events and alarms (once a day as well), then they are copied out with the database to the same place in the network. This folder containing the database and the events-alarms in the network is for other engineers to analize, make calculations, projections, etc. It is weird for me and for the others to have this alarm every day in the events-alarms files of each system.
    Each system is independent, doesn't need to have connection with the other systems. There are no clients because the database collection is enough for us. The systems are VERY STABLE, no need to trouble-shoot (remote access), or even checking how they are working. Truly, Lookout shows a good performance with this application. By the way, the application is too extensive, complex, many different things are controlled and monitored, many different communication protocols are used: OPC servers, Serial connections, etc. General speaking, the overall result is excellent. This little, no-reason alarm is the only problem: "Client License Limit Exceeded".
    I'll really appreciate any suggestion regarding this issue.

Maybe you are looking for

  • Finding count of duplicates in a table

    Hi All, I want to know the count of duplicate rows in a table ? below is a sample for your reference. DB is oracle 10G 10.2.0.1 col A    col B    col C   col D 1         2        3       null 1         2        3       null 3         4        5      

  • AS91 - takeover values coming with grey mode

    Hi, While doing As91 system is giving grey mode for cumm acquisation value and accumalated depreciation value under takeover values tab. Can any body tell me what could be the reason. govind.

  • GC upgrade 10.2.0.1 to 10.2.0.3

    Grid Control on Solaris 10 unzip patch p3731593_10203_SOLARIS64.zip and try to upgrade OMS to 10.2.0.3 but received following error in installation log file. (all pre installation patch already applied. i.e. 4329444 and 5330513(agent) as well) INFO:

  • Remote iSight Software

    I have a mac on my desk (iMac) as well as a MBP that I carry with me. Is there any software application I can install to allow me to stream, either on the same network or over the internet, my iSight video from one computer to another?

  • Clean install problems imac5.2

    Hi, I did a clean install on my mothers old imac 5.2 operating on Tiger, unfortunately the install disc was damaged and I was unable to either complete the installation ( it gets 79% of the way through then fails) or restore the original OS. I just g