cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1277
Views
0
Helpful
10
Replies

Managing VPN HW Client 3002.

andrea.meconi
Level 2
Level 2

Hello.

I'm using LMS 2.6, with RME 4.0.6, to manage Cisco VPN HW client.

I'm receiving the attacked result from sync archive job.

Any idea?

Many thanks.

Regards.

Andrea

10 Replies 10

Derek Clothier
Level 1
Level 1

Hi Andrea,

     The VPN3002 is suppported in RME 4.0.6 (LMS 2.6) - http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_resource_manager_essentials/4.0.5/device_support/table/RME405.html#wp231589

    For Config Fethc however, the only supported protocol for the VPN3002 is HTTPS - http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_resource_manager_essentials/4.0.5/device_support/table/RME405CM.html#SecurityandVPN

    You'll need to do the following 3 things in order to get this to work :

1. Add HTTPS credentials to DCR for your VPN3002 (Common Services -> Device and Credentials -> Device Management then Edit Credentials)

2. Add HTTPS to the list of Transport Protocols to be used by Config Archive (RME -> Administration -> Config Mgmt -> Transport Settings then Add HTTPS to the 'Selected Protocol Order List'

3. Enable HTTPS on the VPN3002 Concentrator http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/4_7/config/tunnel.htm#wp1309633

Regards

Derek Clothier

Hello Derek and many thanks for your help.

With a job RME can fetch the config successfully but doesn't create a archive for this device and returns an error CM0021.

See attachement.

Regards.

Andrea

Any ideas?

Thanks.

Andrea

Hi Andrea,

     Apologies for the slow response.

     The message "CM0210 Unable to generate processed config" indicates that RME is having problems parsing the configuration of your VPN3000 in order to generate the 'Processed Config'  I've been doing some searching.  I think you are most likely hitting a known bug CSCsa35538 - "Config archival  failed for VPN device" . The release note for which reads as follows :

Symptom:

Configuration fetch for VPN 3000 devices fails.

Conditions:

Configuration fetch for VPN 3000 devices fails if there are characters like '<','>' in the configuration file.

Workaround:
Workaround is to remove those characters from the configuratio file. For XML parsers these characters are the delimiters.

As well as the characters mentioned in the bug, I've also found a couple of previous cases where the problem was also caused by the character '&' in the configuration.  Please check your VPN3000 config

Regards

Derek Clothier

Hello Derek and many thanks for your help.

I removed all special characters from config without success.

CM0057 PRIMARY RUNNING Config fetch SUCCESS, archival failed for vpn-contarini Cause: CM0210 Unable to generate processed config Action: Verify that archive exists for device.

Now I'm going to do some tests with another 3002.

Regards.

Andrea

Hi Andrea,

     If you can EMail me the current config of your VPN3002, I'll take a look at it. I can't get the developres involvd as LMS 2.6 that you are running is end of software support and will be completely end of support at the end of June 2011 ( Refer http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps6504/ps6528/ps2425/prod_end-of-life_notice0900aecd80532c07.html )

Regards

Derek

(dclothi@cisco.com) .

Hi Andrea,

     If you can't share the config of your VPN3002 with me you'll need to do the following :

1. Turn on debugging for RME Archive Management

RME -> Admin -> System Preferences -> Log level


application =Archivemgmt  and put both Archive Service and Archive
Client to debug mode. then apply.
2. Run another sync archive job for vpn-contarini
3. When that has completed turn of the debugging in Step 1 and send me the following files :
* All of the Job logs under CSCOpx/files/rme/jobs/dcma or ArchiveMgt/
* CSCOpx/log/dcmaservice.log

Regards
Derek Clothier

Hi Derek.

Attached you can find all logs.

Many many thanks.

Regards.

Andrea

Hi Andrea,

          According to the RME 4.0.5 Supported Devices documentation , for the VPN 3002 you need to be running a minimum of 3.0.2 software - http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_resource_manager_essentials/4.0.5/device_support/table/RME405.html#wp231589

In the first part of the config file you sent me yesterday I see [Version 1.22]  , which I presume means it's running software version 1.22 which isn't supported.  If that's the cse, then you'll need to upgrade to the minimum of 3.0.2 in order to get this to work.

Regards

Derek Clothier

Hi Derek.

VPN 3002 is running software version 4.7.2L.

Regards.

Andrea

Review Cisco Networking for a $25 gift card