cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
60310
Views
30
Helpful
79
Replies

Talos Connectivity Problem

Ditter
Level 8
Level 8

Hi to all ,

i am getting many messages as the following:

Severity: critical
Module: Talos Communication
Description: 3 modules failed:

  • * URLDB- Failed to retrieve beaker inventory
  • * LSP- Failed to retrieve beaker inventory

My subscription is active (it expires in 2026).  

Any ideas about why is this happening?   Is it a problem that has to do with Talos?

Please note that this is the first time i get this message. 

The only change i did some days ago was to change the "Cached URLs Expire" which was set to never and i changed it to "week" but i do not think that my issue has something to do with it.

Any ideas,

Thanks, 

Ditter.

79 Replies 79

Jumping in on this thread because my ha pair just started doing this too. If you can post a fix from your tac case, I'd appreciate it.

pncisco216
Level 3
Level 3

I tried a couple more things and managed to fix this, so didn't get around to talking to Cisco TAC.  I switched the HA roles and made the secondary FMC (with the valid certificate) the active one, and the primary FMC (with the expired certificate) the standby one.  Following that I did a roll back and reinstall of the VDB.  Then I reversed the HA roles again, so that the primary was once again the active one.  It was at this point that I noticed that the certificate was now updated on both FMCs in the HA pair.  I didn't check between steps, so I am not sure if the HA failover was sufficient or if the VBD reinstall was required, as well.  Also, following this the Smart licensing was not seeing the base license for some reason on some of the devices, so I had to de-register/register and apply the licenses again.  This is what worked for me, but if you want an official fix then you may want to talk to Cisco TAC.

Loebmann
Frequent Visitor
Frequent Visitor

I finally received a new certificate. I only have a single FMC with version 7.7.12.

With the help of Sherlock, I was able to narrow down the problem to the Cisco Security Cloud. Re-registration the day before didn't work. Today, I generated a new tenant during the second cloud registration, and after a short time, a new certificate can now be found under /var/sf/beaker3/. Let's see how the automatic renewal works next year.

bucky-fan-mike
Community Member

Just wanted to throw out there that this issue isn't limited to FMC. I just upgraded our 1230's to 7.7.13 and got the error: TalosAgent- couldn't make the initial connection. Checking the certificate and it expired on August 31st:

Certificate:
Data:
Version: 3 (0x2)
Serial Number: 95913372 (0x5b7859c)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, ST = California, L = San Jose, O = Cisco Systems Inc., OU = Security, CN = Keymaster CA 2
Validity
Not Before: Aug 27 15:51:59 2025 GMT
Not After : Aug 31 15:51:59 2026 GMT

I have a TAC case open and hoping for a permanent fix instead of the short term fix of restarting the beaker3 process. Our 1k's have the problem as well. Ironically, our FMC (Single Node on 7.7.13) happens to be fine. Cert on it expires in 2027. 

pncisco216
Level 3
Level 3

Hello again.  I upgraded my FMC HA pair to 7.6.6 today to patch the vulnerabilities released this week, and I ran into this issue again.  Maybe the patch was released containing the expired certificate?  After the upgrade the Primary/Active FMC had the expired certificate from August 31st again, and the Secondary/Standby HA had the new certificate.  I had to go through the HA failover and VDB roll-back/re-install process that I did last time to get the certificate to renew.  In my case, it seems like only the currently standby FMC certificate automatically updates.

Review Cisco Networking for a $25 gift card