cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
58413
Views
30
Helpful
77
Replies

Talos Connectivity Problem

Ditter
Level 8
Level 8

Hi to all ,

i am getting many messages as the following:

Severity: critical
Module: Talos Communication
Description: 3 modules failed:

  • * URLDB- Failed to retrieve beaker inventory
  • * LSP- Failed to retrieve beaker inventory

My subscription is active (it expires in 2026).  

Any ideas about why is this happening?   Is it a problem that has to do with Talos?

Please note that this is the first time i get this message. 

The only change i did some days ago was to change the "Cached URLs Expire" which was set to never and i changed it to "week" but i do not think that my issue has something to do with it.

Any ideas,

Thanks, 

Ditter.

77 Replies 77

No sooner has the certificate expired than the messages start coming in again 😞

Ditter
Level 8
Level 8

@Loebmann In my case i just checked it says:

Validity
Not Before: Sep 14 16:32:06 2025 GMT
Not After : Sep 13 16:32:06 2026 GMT

So i see it is valid up to 13 of Sep 2026.   

But i get several warnings occasionally (my last message was on 18 of Sep 2025) but i firmly believe that they will come back 🙂

Module: Talos Communication
Description: 1 modules failed:

  • * LSP- Failed to retrieve beaker inventory

Ditter

s_SiD_s
Level 6
Level 6

Good day!
fresh install 7.6 and upgraded to Version 7.6.2.1 (build 3) and FMC and FTDv
same error happens LSP-Failed to retrieve beaker inventory
pmtool restartbyid talosAgent
pmtool restartbyid beaker3
make warning go away...
i've chcked cert.
Validity
Not Before: Jan 30 22:32:39 2024 GMT
Not After : Mar 30 22:32:39 2025 GMT 
it is odd that it is still happens)

jwornstaff
Level 3
Level 3

Still receiving the critical LSP alerts in 7.7.11. Restarting beaker3 process clears the alert for about 12 hours and returns....so ignoring. I have personnel monitoring the health status and get called everyday. I tried multiple images from 7.4 to 7.6 to 7.7 and same thing. Along with all the work arounds and just comes back.

You need to check the certificate under “openssl x509 -text -in /var/sf/beaker3/securefirewall-dev-prod-01_prod.pem”.
Once it has expired, the error message appears. However, I have not yet been able to determine why the FMC cannot obtain a new certificate. All configuration adjustments on Cisco's part were unsuccessful. During the last update from 7.7.10 to 7.7.11, I received a new certificate that is valid until August 2026. I hope that it will always be updated automatically in future updates.

s_SiD_s
Level 6
Level 6

I have caught an alarm today, that never seen before)

FMC 7.6.5-106
FTDv-HA 7.6.4-69

Talos Connectivity Status Apr 15, 2026 11:10 AM 1 modules failed: * Enrichment- failed to perform batch query: rpc error: code = Internal desc = Internal error occurred: Request failure: connection error: timed out

root@fmc:/var/sf/beaker3# openssl x509 -text -in securefirewall-dev-prod-01_prod.pem
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 95913372 (0x5b7859c)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, ST = California, L = San Jose, O = Cisco Systems Inc., OU = Security, CN = Keymaster CA 2
Validity
Not Before: Aug 27 15:51:59 2025 GMT
Not After : Aug 31 15:51:59 2026 GMT
Subject: CN = securefirewall-cdfmc-eng-prod-02, C = US, ST = California, L = San Jose, O = Cisco, OU = Security
Subject Public Key Info:

So, I restarted
root@fmc:/var/sf/beaker3# pmtool restartbyid talosAgent
root@fmc:/var/sf/beaker3# pmtool restartbyid beaker3

error gone.

 

 

  - @s_SiD_s        Have a look at : https://bst.cisco.com/bugsearch/bug/CSCwq37578?rfs=qvred
                            I think the bug report is not exactly aligned with your issue but it also contains
                                     'failed to perform batch query' ;
                           which may give you insights , possible reason for ,  ... concerning your  topic

  M.



-- ' Listen to the wind, it talks  
          Listen to the silence, it speaks
             Listen to your heart, it knows
Ganado Mucho (1809 to 1893 ) Navajo Indian

i do not have cloud services enabled.
this is first time error is seen.
will keep an eye on it)

s_SiD_s
Level 6
Level 6

today againg this warning appears...

Software
1 Management Center 7.6.5 (build 106)
2 Devices 7.6.4 (Build 69)
VDB
1 Management Center 433

Talos Connectivity Status
Jul 20, 2026 4:52 PM
1 modules failed:

* Enrichment- failed to perform batch query: rpc error: code = Internal desc = Internal error occurred: Request failure: connection error: timed out

pmtool restartbyid beaker3

pmtool restartbyid talosAgent

did the trick 🙂

s_SiD_s
Level 6
Level 6

Again 🙂

Screenshot_1.png

it was Warning, now it is Critical alarm...
I did it again...

root@FTDv1:/home/admin# pmtool restartbyid beaker3
root@FTDv1:/home/admin# pmtool restartbyid talosAgent

pncisco216
Level 2
Level 2

I am having a similar issue, with the same certificate that expired August 31st.  Seeing messages "Failed to retrieve beaker inventory" as well as "URL Filtering download failure", which I am thinking are related to the same certificate issue.  I pmtool restarts are only a temporary fix, and I have been unable to determine why the certificate is not auto-renewing.  The FMC is version 7.6.5-106 plus Hotfix_CY-7.6.5.1-2.  Is anyone aware of a permanent fix for this?  

root@mgmt-fw-c01-n01:/var/sf/beaker3# openssl x509 -text -in securefirewall-dev-prod-01_prod.pem
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 95913372 (0x5b7859c)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, ST = California, L = San Jose, O = Cisco Systems Inc., OU = Security, CN = Keymaster CA 2
Validity
Not Before: Aug 27 15:51:59 2025 GMT
Not After : Aug 31 15:51:59 2026 GMT
Subject: CN = securefirewall-cdfmc-eng-prod-02, C = US, ST = California, L = San Jose, O = Cisco, OU = Security

 

 

@pncisco216 is your VDB current?

pncisco216
Level 2
Level 2

Yes, VDB 435 (Aug 10th) is installed.  I have just made another observation.  We have an HA pair of FMCs, and the certificate on the secondary (standby) FMC appears to be updated, while the primary (active) one is expired as already noted.  From the secondary (standby) FMC, we see that it is valid till Aug 10th 2027.

admin@mgmt-fw-c01-n02:/var/sf/beaker3$ openssl x509 -text -in securefirewall-dev-prod-01_prod.pem
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 111688043 (0x6a8396b)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, ST = California, L = San Jose, O = Cisco Systems Inc., OU = Security, CN = Keymaster CA 2
Validity
Not Before: Aug 11 13:00:28 2026 GMT
Not After : Aug 10 13:00:28 2027 GMT
Subject: CN = c5315466-992e-11ee-9167-f4cdc6987eef, O = Firepower Organization

Also, looking at the file dates, we see that the certificate on the primary (active) FMC has not been touched since Feb 11, 2026.

FMC Primary (active):  -rw-r--r-- 1 www www 2984 Feb 11 2026 securefirewall-dev-prod-01_prod.pem

FMC Secondary (standby):  -rw-r--r-- 1 root root 2920 Aug 11 13:00 securefirewall-dev-prod-01_prod.pem

I also tried a rollback to VDB 434, and then reinstalled VDB 435 from a fresh download, and there was no change.  The certificate on the primary (active) FMC remains expired.

 

Thanks for those details @pncisco216.

Based on what you are seeing, I suspect you are hitting a use case that was not resolved by the earlier bug fix that should have been incorporated as part of running a current VDB definition set.

I would recommend a TAC case as they will be able to verify and, if necessary, either implement a more permanent work around from the expert cli or else open a fresh bug with development.

pncisco216
Level 2
Level 2

Thank you for looking that over Marvin.

I will submit a TAC case.

Review Cisco Networking for a $25 gift card