I install IDSM service pack "IDSM-sp-3.0-4-S20" and i make also upgrade for CSPM after install the service pack my ids stop sending event to cspm and no event appear at data base could some one help please
Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you. If you don't get a suitable response to your post, you may wish to review our resources at the online Technical Assistance Center (http://www.cisco.com/tac) or speak with a TAC engineer. You can open a TAC case online at http://www.cisco.com/tac/caseopen
If anyone else in the forum has some advice, please reply to this thread.
Alaa, Have you resolved this issue yet? I am currently working with TAC to try to resolve this problem. If you have found a solution send me an email at firstname.lastname@example.org . If TAC gets this figured out I will send you what we did to fix it. Thanks
Stanley Karunditu at TAC came up with the solution to my problem, maybe it will work for you also.
1. If you are able to get into CSPM go to File --> Export and export to a known location that is not associated with CSPM.
2. If you are not able to bring up the gui then use Windows Exporer and browse to the following location. (E:\Program Files\Cisco Secure Policy Manager\Backup) Sort by date and copy the last two or three .cpm files. Note: pu is created when you do an update and the db is created with you click the save button. It does not matter which one you get.
3. Close CSPM if not closed already.
4. Go to Start --> Programs --> Cisco Systems --> Cisco Secure Policy Manager --> CSPM Tools (if you are running 3.0) --> Troubleshooting ToolKit
5. Locate the Restore Policy Database tab
6. Leave the default options and click Restore.
7. The Greyed out boxes will be populated with check marks as CSPM go through the Restore process. (Can take up to 30 seconds)
8. When all the boxes are populated with check marks then click OK.
9. Bring up CSPM normally
10. Import the saved .cpm file. (File --> Import)
11. Click Update to build your database again.
It may tell you that you have an imported administrator. Just delete it.
This process will Restore you Database to new. You will loose all your configuration but you will be able to rebuild your database by importing your .cpm file in and clicking update. If this process does not work then your only other option will be a un-install --> restart system --> re-install.
I had the same issue not too long ago. I updated the IDS & CSPM with S23 update. The CSPM was able to update to all of my sensors but I was not receiving any events back from them. I tried reinstalling an older database, & power off & on the sensors all of which did not work. It almost came down to reinstalling the CSPM until a power failure fixed the problem. My co-worker pointed out that the power failure resetted the ports on the facility cisco switches which corrected the communication problem. He mentioned that sometimes the ports could "fall asleep" for a lack of a better term & probably needed to be resetted. I hope this helps.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in HA
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationCo...
I am currently unable to specify "crypto keyring" command when configuring VPN connection on my cisco 2901 router.
The following licenses have been activated on my router :