<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Signature updates and CSM error message in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677217#M56759</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Dustin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I applied S586 yesterday via CSM (version 3.3 SP1).&amp;nbsp; Of 14 sensors, 7 successful and 7 failed messages.&amp;nbsp; For the 7 failed messages, the sensor update has taken place and no reboot of device (no reboot for successsful devices either).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensors are running 7.0(2)E4 code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Liam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Aug 2011 13:16:28 GMT</pubDate>
    <dc:creator>liamwalk1971</dc:creator>
    <dc:date>2011-08-02T13:16:28Z</dc:date>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677211#M56680</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have started getting the following error message in CSM when pushing signature updates to our 4200 series and IDSM-II blades: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Could not get device version after pushing down sensor update package to device&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The actual signature updates work fine, but just wondering if I can get rid of this error message.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:42:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677211#M56680</guid>
      <dc:creator>liamwalk1971</dc:creator>
      <dc:date>2019-03-10T20:42:39Z</dc:date>
    </item>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677212#M56699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mr Walker,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I received that error quite a bit myself working with the IPS modules and here is how I usually approach it.&amp;nbsp; I have found that sometimes the sensor locks up after the upgrade; in which case, the sensor needs to be rebooted.&amp;nbsp; Most times however, I can redeploy the signature and then CSM will determine the signature is is already applied and state the update is not required or I also found that I can Discover the Policy Inventory and deploy it and that syncs everything back up.&amp;nbsp; Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 21:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677212#M56699</guid>
      <dc:creator>Jonathan Grant</dc:creator>
      <dc:date>2011-07-26T21:05:15Z</dc:date>
    </item>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677213#M56718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jonathan - thanks for the reply....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The signature upgrade actually works and I have not had any issues with sensors locking up - I just get the message about not being able to obtain version details.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 08:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677213#M56718</guid>
      <dc:creator>liamwalk1971</dc:creator>
      <dc:date>2011-07-27T08:15:46Z</dc:date>
    </item>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677214#M56734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That sounds like a timeout message following a signature definition update deployment. I.e. after CSM deploys the signature update package to your managed sensor device(s), it attempts to check-in with the device (following the installation of the update) to retrieve the live version information (to confirm that the update completed successfully). Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;CSM begins deployment of signature definition update to sensor device.&lt;/LI&gt;&lt;LI&gt;Sensor receives update package, begins installation.&lt;/LI&gt;&lt;LI&gt;CSM checks-in with sensor for status update; if sensor is still busy with update installation, this times out.&lt;/LI&gt;&lt;LI&gt;Eventually the repeated timeouts result in the message encountered.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can post the entire deployment log text for review, we may be able to confirm that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 12:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677214#M56734</guid>
      <dc:creator>Dustin Ralich</dc:creator>
      <dc:date>2011-07-28T12:31:25Z</dc:date>
    </item>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677215#M56745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Dustin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the deployment log for one of the devices:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device version before update is: 7.0(2)E4S581.0&lt;/P&gt;&lt;P&gt;Going to send the following package(s) to sensor: IPS-CS-MGR-sig-S583-req-E4.zip, &lt;/P&gt;&lt;P&gt;Processing package file: IPS-CS-MGR-sig-S583-req-E4.zip&lt;/P&gt;&lt;P&gt;Package is ready for update&lt;/P&gt;&lt;P&gt;Checking analysis engine status from device XXXXXX&lt;/P&gt;&lt;P&gt;Analysis engine is up running and device is ready to take updates&lt;/P&gt;&lt;P&gt;Pushing package: IPS-sig-S583-req-E4.pkg to device&lt;/P&gt;&lt;P&gt;Device did not respond to pushUpgrade command from CSM. It may have been upgraded. Will query to find out&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (1/16)&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (2/16)&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (3/16)&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (4/16)&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (5/16)&lt;/P&gt;&lt;P&gt;Error when trying to update: Could not get device version after pushing down sensor update package to device: XXXXXX. Please access the device using Command Line Interface, and check if it is working properly&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Device version before update is: 7.0(2)E4S581.0&lt;/P&gt;&lt;P&gt;Going to send the following package(s) to sensor: IPS-CS-MGR-sig-S583-req-E4.zip, &lt;/P&gt;&lt;P&gt;Processing package file: IPS-CS-MGR-sig-S583-req-E4.zip&lt;/P&gt;&lt;P&gt;Package is ready for update&lt;/P&gt;&lt;P&gt;Checking analysis engine status from device XXXXXX&lt;/P&gt;&lt;P&gt;Analysis engine is up running and device is ready to take updates&lt;BR /&gt;Pushing package: IPS-sig-S583-req-E4.pkg to device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device did not respond to pushUpgrade command from CSM. It may have been upgraded. Will query to find out&lt;BR /&gt;Device not ready, retry getVersion in 30000 milliseconds. (1/16)&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (2/16)&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (3/16)&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (4/16)&lt;/P&gt;&lt;P&gt;Device not ready, retry getVersion in 30000 milliseconds. (5/16)&lt;/P&gt;&lt;P&gt;Error when trying to update: Could not get device version after pushing down sensor update package to device: XXXXXX. Please access the device using Command Line Interface, and check if it is working properly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 08:44:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677215#M56745</guid>
      <dc:creator>liamwalk1971</dc:creator>
      <dc:date>2011-07-29T08:44:37Z</dc:date>
    </item>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677216#M56756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Liam.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the full version of CSM in-use? (You can determine this from the CSM client application &amp;gt; &lt;EM&gt;Help&lt;/EM&gt; menu &amp;gt; &lt;EM&gt;About Security Manager...&lt;/EM&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, you're sure that after this behavior is encountered, the affected sensors actually do appear to have taken and installed the update, but were not rebooted? I.e. their 'show version' output's &lt;EM&gt;Sensor uptime&lt;/EM&gt; value is still incrementing (and not recently reset) but their &lt;EM&gt;Signature Update&lt;/EM&gt; value shows the newly-deployed version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are quite a few now-known defects present in the IPS 7.0(2)E4 software that can cause the sensor to experience failures during signature definition update attempts. Given the sheer number of fixes made post-7.0(2)E4, the first thing to do would be upgrade the affected sensors to 7.0(5a)E4, then re-test to see if the issue still occurs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;I have started getting the following error message in CSM when pushing signature updates to our 4200 series and IDSM-II blades&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Could you let us know specifically what models of the 4200-series platform?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 13:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677216#M56756</guid>
      <dc:creator>Dustin Ralich</dc:creator>
      <dc:date>2011-08-02T13:04:19Z</dc:date>
    </item>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677217#M56759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Dustin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I applied S586 yesterday via CSM (version 3.3 SP1).&amp;nbsp; Of 14 sensors, 7 successful and 7 failed messages.&amp;nbsp; For the 7 failed messages, the sensor update has taken place and no reboot of device (no reboot for successsful devices either).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensors are running 7.0(2)E4 code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Liam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 13:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677217#M56759</guid>
      <dc:creator>liamwalk1971</dc:creator>
      <dc:date>2011-08-02T13:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677218#M56767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Liam. I suspect you are encountering defect &lt;A href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsz37841"&gt;CSCsz37841 (CSM can't upgrade signature with "could not get device version" message)&lt;/A&gt;&amp;nbsp; - fixed in CSM 3.3.1. That defect's Release Note is a little misleading (it just mentions the AIM-IPS sensor model platform, but in reality, this could apply to any sensor model; it is just more likely to apply to the lower-end models). I will update the Release Note to clarify that, but it will take some time before my changes are reflected online.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to upgrade CSM to 3.3.1 to correct this (and ideally, after you upgrade to 3.3.1, you should apply 3.3.1 Service Pack 3, as it includes several more related fixes).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, as mentioned, it also wouldn't hurt to upgrade your sensors to 7.0(5a)E4 for the sheer number of included fixes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 12:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677218#M56767</guid>
      <dc:creator>Dustin Ralich</dc:creator>
      <dc:date>2011-08-05T12:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677219#M56778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dustin...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm about to upgrade the sensors to 7.0(5a)E4 and if that does not resolve the issue, I'll look to upgrade CSM to 3.3.1.&amp;nbsp; I had some pain with the last CSM upgrade, so hopefully it won't come to that again!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Liam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 12:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677219#M56778</guid>
      <dc:creator>liamwalk1971</dc:creator>
      <dc:date>2011-08-05T12:50:35Z</dc:date>
    </item>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677220#M56790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I thought Cisco only supported the current and previous versions of CSM (that would now be 4.1 and 4.0).&lt;/P&gt;&lt;P&gt;Liam, a heads up on your 4.x upgrades: 4.0 requires you to (re)purchase your Base50 license for CSM and 4.1 requires you to run it on a 64 bit OS. If you are upgrading your CSM like the rest of us it means buying and installing a new version of W2K8 enterprise. &lt;/P&gt;&lt;P&gt;Good luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 20:36:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677220#M56790</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-08-05T20:36:52Z</dc:date>
    </item>
    <item>
      <title>Signature updates and CSM error message</title>
      <link>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677221#M56799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt; I thought Cisco only supported the current and previous versions of CSM (that would now be 4.1 and 4.0).&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;To my knowledge, no EoS/EoL has been announced for CSM 3.3 yet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6498/prod_eol_notices_list.html"&gt;http://www.cisco.com/en/US/products/ps6498/prod_eol_notices_list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said, (and this does not constitute any official development/engineering statement on behalf of anybody), generally engineering teams (not specific to Cisco) would probably prefer to not have to support several different release trains simultaneously, and instead focus their efforts on one or two (or a few).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;4.1 requires you to run it on a 64 bit OS. If you are upgrading your CSM like the rest of us it means buying and installing a new version of W2K8 enterprise.&lt;/PRE&gt;&lt;P&gt;The System Requirements do differ (significantly) between 3.3, 4.0[1], and 4.1, and yes, as with any major upgrade, reviewing the Release Notes, System Requirements, etc. before upgrading would be advisable and best-practice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 13:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-updates-and-csm-error-message/m-p/1677221#M56799</guid>
      <dc:creator>Dustin Ralich</dc:creator>
      <dc:date>2011-08-08T13:12:55Z</dc:date>
    </item>
  </channel>
</rss>

