• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 909
  • Last Modified:

Cisco LMS 4.1

Gentlemen,

Greetings!

Our company recently installed a fresh copy of Cisc LMS Prime 4.1.
I have so far configured it  to discover all of the cisco devices on our network.
The problem is, when I try to copy a configuration from 3750 switches to the LMS tftp,
the switch displays an error message that say the copy failed due to an "access denied".

I have been told this is due to the tftp server not being set up properly.  I would think
that an application as robust as Ciosco Works would have the tftp sever already preconfigured after the initial install?

Note:  The apllication resides on a Windows 2k8 server and a TACACS server is used
in conjuction with the LMS for authentication.

Thanks in advance!

rayneedssomehelp
0
Rayneedssomehelp
Asked:
Rayneedssomehelp
  • 4
  • 3
1 Solution
 
ArneLoviusCommented:
are you able to connect with a tftp client ?

could a firewall rule be being pushed out via GPO ?

could there be something else in the traffic path that is "interfering" with tftp ?
0
 
Ken BooneNetwork ConsultantCommented:
A few things.  When I am managing a network with LMS I always set up management IP addresses on all my boxes.  Don't know if you did this or not.  But when a cisco router or switch originates a packet - i.e. you telnet from the router, you tftp from the switch, etc..  The source IP address is always the ip address on the egress interface.  The management IP address I configured is sometimes not the egress interface.  So you can add the following command:

ip tftp source interface vlan255

This will set the source ip address for all tftp originated traffic to the IP address configured on the SVI for vlan 255.

At that point you know exactly what IP address you are dealing with when examining firewalls, ACL, or entries into LMS.

I don't recall ever having to go in and turn on the tftp service with any version of LMS.  I have seen folks install it on a machine that already had a tftp server running , and that of course hosed it up.

What I will say is this.  With 99% of the problems you run into with LMS you will have to open a TAC case.  The documentation is horrible and the product is not intuitive.  Once its up and running it is very powerful and does a great job, but resolving issues seems to always take a TAC case.  I have been dealing with LMS for 10 years in various accounts and this seems to hold true.
0
 
RayneedssomehelpAuthor Commented:
Hello,

All Cisco devices including the LMS serverare in the DMZ.  None of the Cisco devices need to
go through our firewall to communicate with each other...I can ping the server and vice versa from the devices.


We are using private loopback IP's for management on all the Cisco devices.  We previously
employed Solarwinds and What't Up Gold and had no issues with tftp.  Our network
topology has NOT changed duing this time.

I have been  seeing blogs that mentioned the "causer" and a folder that needs to be created
for the tftp server to fuction properly, but I can't find anything in the LMS help files that talk
about this.

How do I even get to the tftp server to change or edit settings?
Where is it located on the LMS application?   I can't find any paths to it!

rayneedssomehelp
0
Choose an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

 
Ken BooneNetwork ConsultantCommented:
That is precisely my point.  The docs are awful.  Knowing that you are managing the devices with a loopback, you should set the ip source tftp interface to that loopback.
0
 
RayneedssomehelpAuthor Commented:
I get that part, but where in the application is the config files saved on the tftp server?
And where can I make settings changes for the tftp server?

Thanks!

rayneedssomehelp
0
 
Ken BooneNetwork ConsultantCommented:
Well from what I see the only setting or setup that needs to be done for the tftp server is for solaris only.  I haven't dealt with that for years.  I don't recall any setup as far as enabling the tftp server goes.  I think it is setup and running by default.

Now the files should be in the following location:
NMSROOT\files\rme\dcma
Where NMSROOT is the Cisco Prime installed directory.

But in earlier versions it was in a shadow directory about 10 levels deep.  Look there and see what you got.. but if you run a config archive job and they all fail, there won't be anything there.
0
 
RayneedssomehelpAuthor Commented:
What about this folder for Smart Installs called TFTP Boot.  I am understanding that this folder
needs to be created,  in order for image or config file deployment to be successful.

Would this be the same file\folder be used to save images or configuration files from the
client\devices to the tftp server?

Thanks,

rayneedssomehelp
0
 
Ken BooneNetwork ConsultantCommented:
I don't know about the smart installs.  sorry.
0

Featured Post

Configuration Guide and Best Practices

Read the guide to learn how to orchestrate Data ONTAP, create application-consistent backups and enable fast recovery from NetApp storage snapshots. Version 9.5 also contains performance and scalability enhancements to meet the needs of the largest enterprise environments.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now