CSA agent register

Hello

I am trying to install the CSA on the hosts. I am able to download and install the kits, but it fails to register.

I have defined in the recording control.

I have a firewall between the two but https is allowed.

I get it all the time in the log file:

[2004-12-07 08:41:45.093] [PID = 564] [Csamanager]: registration without message failed error code = 2035

[2004-12-07 08:41:45.093] [PID = 564] [Csamanager]: registration with server VMSManager failure (2035)

[2004-12-07 08:41:45.093] [PID = 564] [Csamanager]: will try again to register in 10 sec

And when you do Active Survey:

[2004-12-07 08:41:54.046] [PID = 564] [Csamanager]: quick survey... Failure (2035).

[2004-12-07 08:41:54.046] [PID = 564] [Csamanager]: conn_check: started

[2004-12-07 08:41:54.093] [PID = 564] [Csamanager]: conn_check: config ip: ok

[2004-12-07 08:41:54.093] [PID = 564] [Csamanager]: conn_check: dns: solved mgmtserver name VMSManager

[2004-12-07 08:41:54.093] [PID = 564] [Csamanager]: conn_check: https: mgmtserver is accessible via https

[2004-12-07 08:41:54.093] [PID = 564] [Csamanager]: conn_check: finished

Any Suggestion?

Thank you and best regards,

Maybe u ran out of licenses to agents?

Tags: Cisco Security

Similar Questions

  • Query for registered agents

    Is there a way to query for all Scheduler agents registered in the database, such as a table of metadata?

    For the moment (11.1.0.7) you do not see that the agents are registered. Cn find you that agents have been used recently by checking the schedulerrun_details view.

    Ronald.
    http://ronr.blogspot.com

    Published by: Ronald Rood on July 23, 2009 10:13

  • CSA v5.2 to v6.0.1 update: not available on CSA 5.2 software update

    Hello

    Today, I upgraded a CSA v5.2 to v6.0.1 on the same physical server.

    During installation, it has been a failure (import data migration) and the installation process could not find the .dat and .xml files in the folder migration\export of the 5.2 cm. All the problems I could solve by exporting of v5.2 and import to v6.0.1 manually.

    When I try to plan a software update on the MC 5.2 to migrate and update agents from 5.2 to 6.0.1 MC, the new software (6.0.1) are not available. Well as they should by the 6.0 installation guide. I guess that something was wrong to register the software updates during the installation process.

    Now CSA v5.2 and v6.0.1 coexist on the same computer and the CSA (version 5.2) agents are still connecting to the MC 5.2. Only the MC CSA agent connects to 6,0 MC.

    Is there a way to make the 6.0 software updates appear on the MC 5.2? So I can use an update scheduled to migrate them to MC 6.0.

    Thanks for your help.

    Kind regards

    Nico

    This looks like a problem that occurs when the command window is closed before the migration is complete.

    You may be able to run the register_software_update.sql script, or use the prepare_52_migration.exe to migrate.

  • CSA 6.01 - kit-list

    Hello dear experts and users, I hope someone can help me. I can't open the kit list on the homepage of the APF-Server (CSA_MC) of any client. I see the message "error: address xxx is not allowed access to the Cisco Security Agent kit list.» My solution is to log in to the CSA server to the remote host and to install the kit in the menu "system or Agent packages. It's not so comfortable...
    I went from the CSA Agent from the server to find the great, but I don't have a missconfigure of the Agent is not the solution.

    Thanks a lot if someone has a good answer, greetings...

    You may put in some addresses in the dialog™ concerning what addresses can register with the™, I think that it blocks access to agent so kits without logging it is.

  • CSA installed 5,2.0.238 on a Win 2 k 3 Server

    The server that I have will deploy with the CSA Agent, must only be attached to the group "Servers - deployed internally" or should it be attached to other groups as well? This server is not a file or print server, but will maintain the newspapers if I don't want the necessary protection.

    Thank you

    Adam

    Yes, I clone everything like I did with 4.X.

    He made the upgrades and management much easier IMHO.

    Tom

  • 6.0 CSA remote desktop and

    I upgraded to 6.0 CSA agent on my PC and when I try desktop remotely to a server, I am not able to. I looked in the newspapers of the CSA and there is not a log message that indicates the action was blocked. I uninstalled CSA and I am able to RDP. All the world experience, and is there a way around it?

    There is no event in the management console as well.

    Thanks in advance!

    With CSA 6.0, network access control rule [1635], were decisive for this access. The request is identified as:

    svhost.exe k termsvcs

    Termsvcs is your terminal services/RDP. Just add an exception to this rule that allows the connection using the host addresses.

  • Install experience with CSA 4.01 & Call Manager

    Someone at - he had luck get the Callmanager XML policy file and use with CSA agent install?

    I was not able to find the custom policy referenced in the doc, they was curious to know if anyone has installed the CSA on a Callmanager sever and what results have been.

    Thank you

    Here is the link to get the custom policy. I installed CSA on Call Manager several months ago. no problem so far.

    http://www.Cisco.com/cgi-bin/tablebuild.pl/CMVA-3DES

    Please do not forget to rate answers

    Thank you

    Travis

  • CSA on servers in the DMZ

    Hello

    I'll install csa agent on servers of DMZ. Since there is no access to the Management Center in the DMZ, access is not permitted from internal dmz, only MC (internal) can access servers. I know that the CSA can record events on the computer, the MC will be able to get back them?

    Except for a hint of polling sending, the MC is not initialize the connection for update of policy officers and events download. Agents are configured with a polling interval (default is 10 minutes), the Agent makes the connection with the MC via port 5401, and if it is not available try 443.

    For your Agents work correctly with the MC, your DMZ must allow your dmz servers to connect to your internal port 5401 or 443 MC (I prefer 443).

    Just add an ACL on your firewall so that the dmz servers can connect to only this server MC. Then you can create a rule to network access control so only the Cisco Security Agent can access the IP address of the MC on port 443.

    In this way even if the attacker has exceeded all the other rules of the csa and used the server dmz as a breakpoint for more attack, they must kill the agent first, before they could get to the MC. And if that wasn't enough, you can create a rule of access control data to the Agent installed on the MC itself, which will send you an email if the root of the https:// is accessible.

  • CSA for Windows Vista?

    Are there details about a release of the CSA for Windows Vista? Or y at - he current CSA releases going to be compatible with Vista?

    Windows Vista is not officially supported as an accommodation for CSA agent OS. For the list of OS supported for CSA officers refer to the following link

    http://Cisco.com/en/us/products/sw/secursw/ps5057/prod_release_note09186a00805aea29.html#wp65968

  • "dsccreg add-server" translates to "DSCC Agent not found"

    Hello

    I have set up two servers, 'ldap1' and 'ldap2', the two 7-Department (11.1.1.7.0) running with DSCC configured on ldap1.  On ldap1, the DSCC agent runs:

    root@ldap1:~#/opt/dsee7/bin/dsccagent info - v

    The instance path: / opt/dsee7/var/dcc/agent

    Owner: root

    JMX port: 3997

    SNMP port: disabled

    Status: running

    PID: 25898

    DSCC hostname: ldap1.utica.edu

    Port not secure from DSCC: 3998

    Port secure DSCC: 3999

    The instance version: A - A00

    I was able to save its own DS to DSCC instance by running the following:

    root@ldap1:~#/opt/dsee7/bin/dsccreg server add - v h ldap1.utica.edu h ldap1.utica.edu d ldap1-dsins1/var/opt/dsee7/dsins1

    Enter the password of the administrator DSCC:

    DSCC administrator password is OK

    Creation of trust cert

    Create the KeyStore file OK; try to connect...

    / var/opt/dsee7/dsins1 is an instance of DS

    DSCC administrator password is OK

    Creation of trust cert

    Create the KeyStore file OK; try to connect...

    Agent no. Hostname Port owner iPath

    --------  ---------------  ----  -----  ------------------------

    0 ldap1.utica.edu 3997 root/opt/dsee7/var/dcc/agent

    The recording will be use DSCC agent on port: 3997

    Enter the password of "cn" = Directory Manager for/var/opt/dsee7/dsins1:

    This operation will restart/var/opt/dsee7/dsins1.

    Do you want to continue? y (y/n)

    Connection to/var/opt/dsee7/dsins1 (via ldap://127.0.0.1:389)

    Allowing the DSCC access to/var/opt/dsee7/dsins1

    / Var/opt/dsee7/dsins1 restart

    Registration/var/opt/dsee7/dsins1 to DSCC on ldap1.utica.edu.

    You are looking for an entry "cn=ldap1.utica.edu@/var/opt/dsee7/dsins1,cn=Servers,cn=dscc".

    However, when I try to register the instance of DS on ldap2 with the DSCC instance on ldap1, I get the following:

    root@ldap2:~#/opt/dsee7/bin/dsccreg server add - v h ldap2.utica.edu h ldap1.utica.edu d ldap2-dsins1/var/opt/dsee7/dsins1

    Enter the password of the administrator DSCC:

    DSCC administrator password is OK

    Creation of trust cert

    Create the KeyStore file OK; try to connect...

    / var/opt/dsee7/dsins1 is an instance of DS

    DSCC administrator password is OK

    Creation of trust cert

    Create the KeyStore file OK; try to connect...

    No agent DSCC found

    / var/opt/dsee7/dsins1 has not been saved to the DSCC on ldap1.

    Running on ldap1 tcpdump showed that connected to ldap1 on port 3998 ldap2 and there were 51 packets exchanged between these two hosts before ldap2 showed the mistake found no. DSCC agent and abandoned the attempt.  So at least I know that it is not a network problem.  I restarted the DSCC agent on ldap1 several times, but he has not made a difference.

    Anyone know what could be the problem?

    I finally solved the problem.  I needed to create a DSCC agent on the 2nd Department (ldap2) server and point it at the DSCC (ldap1) host:

    root@ldap2:~#/opt/dsee7/bin/dsccreg add-agent - v h ldap1.utica.edu/opt/dsee7/var/dcc/agent

    HostName: ldap2.utica.edu

    Agent path: / opt/dsee7/var/dcc/agent

    Enter DSCC agent "/ opt/dsee7/var/DCC/agent" password:

    Download the config file

    Representative is not already registered; check the password for agent instance

    Password agent instance OK

    Enter the password of the administrator DSCC:

    DSCC administrator password is OK

    Creation of trust cert

    Create the KeyStore file OK; try to connect...

    Try to register the agent:

    Agent port: 3997

    Agent user name: root

    Host name: ldap2.utica.edu

    Instance of agent registered in DSCC; update the agent config file

    Update configuration file:

    Agent/opt/dsee7/var/dcc/agent configuration file updated with:

    Host name of registry = ldap1.utica.edu

    Port of registry = 3998

    Secure registry 3999 = port

    Agent instance was recorded at the DSCC ldap1.utica.edu

    You can now run dsccagent start to start the agent

    root@ldap2:~#/opt/dsee7/bin/dsccagent start

    The/opt/dsee7/var/dcc/agent agent started

    Once this is done, the DSCC registration worked well:

    root@ldap2:~#/opt/dsee7/bin/dsccreg server add - v h ldap2.utica.edu h ldap1.utica.edu d ldap2-dsins1/var/opt/dsee7/dsins1

    Enter the password of the administrator DSCC:

    DSCC administrator password is OK

    Creation of trust cert

    Create the KeyStore file OK; try to connect...

    / var/opt/dsee7/dsins1 is an instance of DS

    DSCC administrator password is OK

    Creation of trust cert

    Create the KeyStore file OK; try to connect...

    Agent no. Hostname Port owner iPath

    --------  ---------------  ----  -----  ------------------------

    0 ldap2.utica.edu 3997 root/opt/dsee7/var/dcc/agent

    The recording will be use DSCC agent on port: 3997

    Enter the password of "cn" = Directory Manager for/var/opt/dsee7/dsins1:

    This operation will restart/var/opt/dsee7/dsins1.

    Do you want to continue? y (y/n)

    Connection to/var/opt/dsee7/dsins1 (via ldap://127.0.0.1:389)

    Allowing the DSCC access to/var/opt/dsee7/dsins1

    / Var/opt/dsee7/dsins1 restart

    Registration/var/opt/dsee7/dsins1 to DSCC on ldap1.utica.edu.

    You are looking for an entry "cn=ldap2.utica.edu@/var/opt/dsee7/dsins1,cn=Servers,cn=dscc".

  • Push not configurable Message after a device reboot java BB

    Hi all

    I joined the BlackBerry push notification successfully in my application of the Sub http://supportforums.blackberry.com/t5/BlackBerry-Push-Development/Simplified-BIS-Push-client-sample...url. Here again successfully able to get push until you restart the device notification, after restarting the device I can't able to get push notification.

    Note: I put the other entry point, checked the "-autorun at startup" and my main method is as below

     if (args != null && args.length > 0 && args[0].equals("autostart")) {
                 // auto start, wait for OS
                while (ApplicationManager.getApplicationManager().inStartup()) {
                   try {
                    Thread.sleep(10000);
                } catch (InterruptedException e) {
                    // TODO Auto-generated catch block
                    e.printStackTrace();
                }
                }
    
                PushAgent agent = new PushAgent();
                agent.register();
                agent.enterEventDispatcher();
    
            } else {
    
                            theApp = new MyApp();
                theApp.enterEventDispatcher();
    
            }        
    

    Is I used something wrong or I have to put in any other place?

    Thanks @gbeukeboom. Finally, I found the solution from this link. http://rincethomas.blogspot.in/2012/07/push-notification-in-BlackBerry.html

  • New Server virtual machines

    I'm building a new server for virtual computers, and I want to keep all databases. I think it's easy the database restores on the new server, but my problem seems to be with the leader of the CSA. Anyone has any ideas on this or I will just have to reinstall the agents?

    Until the new server has the same name of netbios and the IP address as one, then your CSA agents must connect fine.

  • What is 8.55 PeopleTools remote administration

    In peopleTools 8.55 there are remote administration settings in the psappsrv.cfg PSTOOLS section. What are the features and how to use it?

    Values for the config - PSTOOLS section

    Enable Remote Administration = 1

    Administration port remotely = 10100

    Remote Administration UserId = admin

    Remote Administration password = *.

    PeopleSoft Health Center

    ________________________

    Authentication of a component or a field with a JMX Agents, press Enter to collapse

    PeopleSoft Health Center invites you to add components or domains registered with PPM agent for the purposes of surveillance. The monitoring application authenticates these components or areas by asking a Panel on each component or member field. This is a single authentication that is implemented through the JMX agents. You can choose the components or areas to analyze by answering Yes for the option turn on tracing.

    Consider the following when you want to enter username and password for a domain or a component participants:

    • For the web server component (domain PIA), the JMX agent uses the same user name and the password that you enter in the web server administration console.
    • For Tuxedo components (application server and the areas of the process scheduler), the JMX agent uses the user name and password is entered in the field Tuxedo configuration file.

    After you have registered a component or a domain, if you disable JMX agents, registered components will display an error message on the dashboard application. The error message indicates that the component is inaccessible for monitoring.

    To enable or disable JMX agents for the application server and the areas of the process scheduler, you change the value of the parameter enable the Administration to distance in the PSTOOLS of PSADMIN section. Set the value to 1 to enable the JMX agents; sets the value of 0pour disable JMX agents.

    When you set enable Administration 1 remotely, a lightweight daemon rmiregistry process begins on the machine. Several areas on the same machine can share the same rmiregistry process using the same value of parameter of Port of Directors remotely, but these multiple domains must have unique domain names. When the rmiregistry process is started, it is never destroyed until the computer is restarted.

  • script checks to see if the agents are registered in

    Running of the IPCC 4.04

    Is there a way to do an if statement check to see if there is no agent connected to decide whether or not to send it to the queue, or send it to vmail. The case set out in General redirection and vmail, I can do. This is the part about checking to see if the agents are registered in what I need help with. Anyone have any ideas?

    You will need to use 'Get the Statisic of Reporting' and write the value in a field "int". Then, use an "if" statement to verify this value.

    From the 'get Statisic Reporting' use report object CSQ IPCC Express, field is logged resources. Row identifier is CSQ, you want to watch. Result of SEO is the "int" field you can watch with the "if" statement The attachment has an example.

    I hope this helps. Please rate if it does.

  • CSA 6.0.2 software agent failed to gather the configuration sent from the central server

    Have CSA 6.0.2 much workstaitions not answering a similar event:

    The agent software cannot compile configuration sent from the central server:
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(4256): the CSIDL_SYSTEMX86 variable was not declared
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(4550): the CSIDL_SYSTEMX86 variable was not declared
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(4708): the ProcessName variable was not declared
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(4771): the ProcessName variable was not declared
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5155): parse error
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5165): parse error
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5171): parse error
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5192): parse error
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5211): parse error
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5215): parse error
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5236): parse error
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5252): parse error
    (C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5258): parse error
    C:\Program Files\Cisco\CSAgent\cfg\agent.rul(5287)

    You may be experiencing bug CSCtg78612.  This occurs when the CSA MC is updated from a previous version of 6.0 to 6.0.2 and managed agents have not yet been upgraded.  You should be able to solve the problem by programming upgrades the agent for the affected hosts.

    You can view the full bug details here:

    http://Tools.Cisco.com/support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtg78612

    Scott

Maybe you are looking for

  • HD is full

    iMac 27 "2011 with OSX Yosemite 10.10.5. two internal drives a Flash of 250 and a spinningdisk of 2 TB My boot drive is full and I move all the photo and music of HD2, but still he say me that the user (me) consumes 159GB and if I summarized the Dire

  • A thunderbolt 2 displays with Macbook/Thunderbolt cable work?

    Hello, I have two MacBooks, 2012 is thunderbolt, thunderbolt is a new 2. Thunderbolt has a shortage in the thunderbolt port and so I have to buy a cable and doing it this way. Is there a difference in a thunderbolt cable 2 vs 1? Because my 2012 has o

  • HP Pavilion g series: voice of the unwanted ads

    For the first time I'm ads of hearing that seem unrelated to the site I'm.  There is no visible advertising, just noise.  I had to cut the sound, because they were so boring.  How can I get rid of them?

  • Storage of ThinkPad Twist

    Hello! This will be like a silly question, but I can't answer on my own, so I thought I would ask here. My company has just purchased a Lenovo's ThinkPad Twist for me (I'm a big fan of Lenovo). I'm just trying to give a sense specifications for stora

  • Want to configure Media Center to record TV on a network media player

    I installed an Iomega Home Media Drive and expected that I was able to conifgure WCE to use.   Player netwroked folder was located in T: but I can't change the storage location of MCE TV Recorder of C:I can not also any network location drive select