cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
63173
Views
31
Helpful
92
Replies

Talos Connectivity Problem

Ditter
Level 8
Level 8

Hi to all ,

i am getting many messages as the following:

Severity: critical
Module: Talos Communication
Description: 3 modules failed:

  • * URLDB- Failed to retrieve beaker inventory
  • * LSP- Failed to retrieve beaker inventory

My subscription is active (it expires in 2026).  

Any ideas about why is this happening?   Is it a problem that has to do with Talos?

Please note that this is the first time i get this message. 

The only change i did some days ago was to change the "Cached URLs Expire" which was set to never and i changed it to "week" but i do not think that my issue has something to do with it.

Any ideas,

Thanks, 

Ditter.

92 Replies 92

Jumping in on this thread because my ha pair just started doing this too. If you can post a fix from your tac case, I'd appreciate it.

pncisco216
Level 3
Level 3

I tried a couple more things and managed to fix this, so didn't get around to talking to Cisco TAC.  I switched the HA roles and made the secondary FMC (with the valid certificate) the active one, and the primary FMC (with the expired certificate) the standby one.  Following that I did a roll back and reinstall of the VDB.  Then I reversed the HA roles again, so that the primary was once again the active one.  It was at this point that I noticed that the certificate was now updated on both FMCs in the HA pair.  I didn't check between steps, so I am not sure if the HA failover was sufficient or if the VBD reinstall was required, as well.  Also, following this the Smart licensing was not seeing the base license for some reason on some of the devices, so I had to de-register/register and apply the licenses again.  This is what worked for me, but if you want an official fix then you may want to talk to Cisco TAC.

Loebmann
Frequent Visitor
Frequent Visitor

I finally received a new certificate. I only have a single FMC with version 7.7.12.

With the help of Sherlock, I was able to narrow down the problem to the Cisco Security Cloud. Re-registration the day before didn't work. Today, I generated a new tenant during the second cloud registration, and after a short time, a new certificate can now be found under /var/sf/beaker3/. Let's see how the automatic renewal works next year.

bucky-fan-mike
Community Member

Just wanted to throw out there that this issue isn't limited to FMC. I just upgraded our 1230's to 7.7.13 and got the error: TalosAgent- couldn't make the initial connection. Checking the certificate and it expired on August 31st:

Certificate:
Data:
Version: 3 (0x2)
Serial Number: 95913372 (0x5b7859c)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, ST = California, L = San Jose, O = Cisco Systems Inc., OU = Security, CN = Keymaster CA 2
Validity
Not Before: Aug 27 15:51:59 2025 GMT
Not After : Aug 31 15:51:59 2026 GMT

I have a TAC case open and hoping for a permanent fix instead of the short term fix of restarting the beaker3 process. Our 1k's have the problem as well. Ironically, our FMC (Single Node on 7.7.13) happens to be fine. Cert on it expires in 2027. 

pncisco216
Level 3
Level 3

Hello again.  I upgraded my FMC HA pair to 7.6.6 today to patch the vulnerabilities released this week, and I ran into this issue again.  Maybe the patch was released containing the expired certificate?  After the upgrade the Primary/Active FMC had the expired certificate from August 31st again, and the Secondary/Standby HA had the new certificate.  I had to go through the HA failover and VDB roll-back/re-install process that I did last time to get the certificate to renew.  In my case, it seems like only the currently standby FMC certificate automatically updates.

DM11
Frequent Visitor
Frequent Visitor

Hello,

I have exactly the same issue. I have upgraded my FMC HA pair from 7.6.5.2-1 to 7.6.6 and ran into this problem. I have installed the latest VDB before upgrade. After the upgrade the Primary/Active FMC had the expired certificate from August 31st, while the Secondary/Standby HA had the new certificate. Could you please provide the detailed steps on how to renew the certificate on Primary/Active FMC through the HA failover and VDB roll-back/re-install process?
Thanks a lot.

Loebmann
Frequent Visitor
Frequent Visitor

In CSCwo63951:

"On software versions affected by this defect, if FMCs are in HA, the download of a new certificate to the active FMC will not download a new certificate to the standby FMC, since SSEConnector does not run on the standby FMC. To get the certificate onto the current standby FMC, switch FMC HA roles so that the standby FMC becomes active. Then, (re)install a content update (GeoDB or VDB, at least at one of the update versions shown above) to the now-active FMC to initiate the process of installing a new 365-day certificate to the FMC."

DM11
Frequent Visitor
Frequent Visitor

Thanks for the response. However, in my case, the problem is exactly the opposite. After the upgrade the Secondary/Standby HA FMC received the new certificate, valid until 2027, while the Primary/Active FMC still had the expired certificate, which was only valid until August 31, 2026.

I will try to reinstall the VDB on the Primary Unit.

I also saw the bug referred to by Loebmann and it sounded like the opposite certificate situation.  However, the process I followed was the same.  I switched the HA roles (using Switch Peer Roles) to make the Secondary FMC active, and then re-installed the VDB from the currently Secondary/Active FMC.  Checking the certificate on the currently Primary/Standby FMC, I saw that it was now updated.  The bug states that only the active FMC certificate automatically updates, but in my case it seemed as though only the standby certificate automatically updated.  Also, in my case the update had removed all the previous VDB updates, so I had to download the previous one from the support site and upload it to the FMC to be able to do the rollback.  The rollback link with a different icon will appear beside the delete/garbage can on the VDB update page.  After the rollback, I then installed the latest VDB with the install link for that one.  This is my interpretation of "reinstall the VDB", but there may be other ways of doing this.  After all this I used the "Switch Peer Roles" again to return to the Primary/Active - Secondary/Standby HA state with both certificates now updated.  This is what worked in my situation.   

sjohansen86
Community Member

Just thought I'd post an update on this case.

I struggled with this when I updated from 7.7.11 to 7.7.13 where Talos couldn't do the initial connection. This was over a couple of days until I found the answer.

We're running a HA setup of 3110 and our fix was to connect to each instance and run the following command:

"/ngfw/usr/local/sf/bin/start_beaker_process.sh beaker3"

The script was there, but when I attempted to start beaker3 the enable file was missing. After running the script pasted above, the enable file was there and it automatically started the process.

After a couple of minutes all my instances turned green and the error went away.

Another issue is that the 7.7.13.69 update seem to have an old certificate for talos communication it it which I hope automatically updates after a while now that it's connected.

To check if it's the same problem, run pmtool status | grep beaker3 in expert mode. For me it said "Waiting". In /ngfw/var/log/sf/talos_agent.log I also saw "couldn't make the initial local connection to 127.0.0.1:4252" every 5 minutes. This is most likely beaker3 locally on the device, so the problem was not the connection to the cloud at all.

This is probably also why just restarting beaker3 didn't help. I tried that first, but without the enable file (/ngfw/etc/sf/beaker3.run) it just went back to Waiting.

 

s_SiD_s
Level 6
Level 6

i have upgrade FMC to 7.6.6
but still cert is
Not Before: Aug 27 15:51:59 2025 GMT
Not After : Aug 31 15:51:59 2026 GMT
on FMC web Content Updates
Currently installed VDB version: build 437 ( 2026-09-11 07:45:24 )

Running Snort Rule update version:  2026-09-23-001-vrt
Geo
Running geolocation version:  2026-09-19-099
Running Lightweight Security Package (LSP) version:  lsp-rel-20260819-2244

restarted service on cli doen't help
no new VDB...or other updates.
it is really annoynig that Cisco cannot fix this issue fron version to version....behaivour is same ^( it is pitty 

root@fmc:/var/sf/beaker3# openssl x509 -text -in /var/sf/beaker3/securefirewall-dev-prod-01_prod.pem
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 95913372 (0x5b7859c)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, ST = California, L = San Jose, O = Cisco Systems Inc., OU = Security, CN = Keymaster CA 2
Validity
Not Before: Aug 27 15:51:59 2025 GMT
Not After : Aug 31 15:51:59 2026 GMT

 

Just chipping in to say that we're seeing the same issue after upgrading to 7.6.6.
Our FMC is not configured for HA. We restarted the FMC services, but this has not resolved the issue.
Our FMC is also not integrated with Cisco Security Cloud, which is listed as a workaround for CSCwr23982 : Bug Search Tool.   

 

RouteMeMaybe
Community Member

I’m on 7.6.6 as well and seeing exactly the same behavior, although I don’t have an HA pair yet.

Same certificate, including the same serial number and validity:

Serial: 05B7859C
Not Before: Aug 27 15:51:59 2025 GMT
Not After: Aug 31 15:51:59 2026 GMT

VDB 437, SRU 2026-09-23-001-vrt and GeoDB 2026-09-19-099 as well.

Restarting the Talos/Beaker services didn’t renew the certificate either.

In my case there is one more strange issue: I cannot keep automatic GeoDB updates enabled. I enable/configure them, but the setting disables itself again.

So for now I’m waiting for the next GeoDB update to see what happens. Fortunately, at least in my case, this currently seems to be mostly a cosmetic health warning and the security content itself is up to date. 🙂

s_SiD_s
Level 6
Level 6

nobody knows the answer... 🙂 even Cisco itself O_o
Will see if next VDB 43X, SRU LSP updates fixes this "bug"

Review Cisco Networking for a $25 gift card