Link to home
Start Free TrialLog in
Avatar of Rayneedssomehelp
Rayneedssomehelp

asked on

Cisco LMS 4.1

Gentlemen,

Greetings!

Our company recently installed a fresh copy of Cisc LMS Prime 4.1.
I have so far configured it  to discover all of the cisco devices on our network.
The problem is, when I try to copy a configuration from 3750 switches to the LMS tftp,
the switch displays an error message that say the copy failed due to an "access denied".

I have been told this is due to the tftp server not being set up properly.  I would think
that an application as robust as Ciosco Works would have the tftp sever already preconfigured after the initial install?

Note:  The apllication resides on a Windows 2k8 server and a TACACS server is used
in conjuction with the LMS for authentication.

Thanks in advance!

rayneedssomehelp
Avatar of ArneLovius
ArneLovius
Flag of United Kingdom of Great Britain and Northern Ireland image

are you able to connect with a tftp client ?

could a firewall rule be being pushed out via GPO ?

could there be something else in the traffic path that is "interfering" with tftp ?
A few things.  When I am managing a network with LMS I always set up management IP addresses on all my boxes.  Don't know if you did this or not.  But when a cisco router or switch originates a packet - i.e. you telnet from the router, you tftp from the switch, etc..  The source IP address is always the ip address on the egress interface.  The management IP address I configured is sometimes not the egress interface.  So you can add the following command:

ip tftp source interface vlan255

This will set the source ip address for all tftp originated traffic to the IP address configured on the SVI for vlan 255.

At that point you know exactly what IP address you are dealing with when examining firewalls, ACL, or entries into LMS.

I don't recall ever having to go in and turn on the tftp service with any version of LMS.  I have seen folks install it on a machine that already had a tftp server running , and that of course hosed it up.

What I will say is this.  With 99% of the problems you run into with LMS you will have to open a TAC case.  The documentation is horrible and the product is not intuitive.  Once its up and running it is very powerful and does a great job, but resolving issues seems to always take a TAC case.  I have been dealing with LMS for 10 years in various accounts and this seems to hold true.
Avatar of Rayneedssomehelp
Rayneedssomehelp

ASKER

Hello,

All Cisco devices including the LMS serverare in the DMZ.  None of the Cisco devices need to
go through our firewall to communicate with each other...I can ping the server and vice versa from the devices.


We are using private loopback IP's for management on all the Cisco devices.  We previously
employed Solarwinds and What't Up Gold and had no issues with tftp.  Our network
topology has NOT changed duing this time.

I have been  seeing blogs that mentioned the "causer" and a folder that needs to be created
for the tftp server to fuction properly, but I can't find anything in the LMS help files that talk
about this.

How do I even get to the tftp server to change or edit settings?
Where is it located on the LMS application?   I can't find any paths to it!

rayneedssomehelp
That is precisely my point.  The docs are awful.  Knowing that you are managing the devices with a loopback, you should set the ip source tftp interface to that loopback.
I get that part, but where in the application is the config files saved on the tftp server?
And where can I make settings changes for the tftp server?

Thanks!

rayneedssomehelp
Well from what I see the only setting or setup that needs to be done for the tftp server is for solaris only.  I haven't dealt with that for years.  I don't recall any setup as far as enabling the tftp server goes.  I think it is setup and running by default.

Now the files should be in the following location:
NMSROOT\files\rme\dcma
Where NMSROOT is the Cisco Prime installed directory.

But in earlier versions it was in a shadow directory about 10 levels deep.  Look there and see what you got.. but if you run a config archive job and they all fail, there won't be anything there.
What about this folder for Smart Installs called TFTP Boot.  I am understanding that this folder
needs to be created,  in order for image or config file deployment to be successful.

Would this be the same file\folder be used to save images or configuration files from the
client\devices to the tftp server?

Thanks,

rayneedssomehelp
ASKER CERTIFIED SOLUTION
Avatar of Ken Boone
Ken Boone
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial