Guest

CiscoWorks Resource Manager Essentials

Release Notes for Resource Manager Essentials 4.0.5 on Windows

Table Of Contents

Release Notes for Resource Manager Essentials 4.0.5 on Windows

New Features

New Device Support

Product Documentation

Additional Information Online

Caveats

Known Problems in RME 4.0.5

Installation and Upgrade Known Problems

Administrator Known Problems

Device Management Known Problems

Device/Agent Known Problems Impacting ANI Server and RME Functionality

Inventory Known Problems

Archive Management Known Problems

NetConfig Known Problems

Config Editor Known Problems

Netshow Known Problems

Software Management Known Problems

Change Audit Known Problems

Syslog Known Problems

cwcli export Known Problems

Contract Connection Known Problems

Bug Toolkit Known Problems

Server, Browser, UI, and Desktop Known Problems

Common/Other Known Problems

Resolved Problems in RME 4.0.5

Obtaining Documentation

Cisco.com

Product Documentation DVD

Ordering Documentation

Documentation Feedback

Cisco Product Security Overview

Reporting Security Problems in Cisco Products

Obtaining Technical Assistance

Cisco Technical Support & Documentation Website

Submitting a Service Request

Definitions of Service Request Severity

Obtaining Additional Publications and Information

Open Source License Acknowledgements

OpenSSL/Open SSL Project

License Issues


Release Notes for Resource Manager Essentials 4.0.5 on Windows


These Release Notes contain information about new features. They provide pointers to device support information and also provide information about the known and resolved problems in this release.

For the details about the supported Windows versions see the Installation and Setup Guide for Resource Manager Essentials 4.0.5 on Windows.

These Release Notes provide:

New Features

Product Documentation

Additional Information Online

Caveats

Known Problems in RME 4.0.5

Resolved Problems in RME 4.0.5

Obtaining Documentation

Documentation Feedback

Obtaining Technical Assistance

Obtaining Additional Publications and Information

Open Source License Acknowledgements

New Features

This section discusses the new features in RME 4.0.5.

Check Device Attributes: This is now a schedulable job in RME. You can select the credentials that you want to verify, and trigger a job for these credentials. You can access this through the RME Job Browser.

Device Selector: Simple and Advanced Search capabilities are provided in the Enhanced Device Selector.

Functional Homepage: RME now has a new functional homepage from where you can access all reports, carry out frequently used tasks, view status of jobs. You can also view any alert messages.

Performance Tuning Tool (PTT): You can tune system parameters using PTT to improve RME performance.

Reports: Reports have been enhanced to allow group-based selection of devices to generate reports.

Unique Device Identifier UDI: The Detailed Device Report displays Unique Device Identifier as one of the columns for the components available for a particular device.

Each component of a device is identified with a UDI and it is unique. A Unique Device Identifier is a combination of Product ID (PID), Version ID (VID) and Serial Number (SN).

LMS Setup Center: This is a one-stop place that allows you to set basic configuration for the applications.

For more details, see the User Guide for Resource Manager Essentials.

New Device Support

For a list of all devices supported in RME 4.0.5, including devices supported in previous versions of RME, see the Supported Device Table for Resource Manager Essentials 4.0.5 on Cisco.com:

http://www.cisco.com/en/US/products/sw/cscowork/ps2073/products_device_support_tables_list.html

Product Documentation


Note We sometimes update the printed and electronic documentation after original publication. Therefore, you should also review the documentation on Cisco.com for any updates.


The following documents are provided in PDF on your product CD:

Installation and Setup Guide for Resource Manager Essentials on Windows

User Guide for Resource Manager Essentials


Note Adobe Acrobat Reader 6.0 or later is required.


Use these guides to learn how to install and use Resource Manager Essentials 4.0.5:

Installation and Set Up Guide for Resource Manager Essentials on Windows — Provides installation instructions, including both server and client system requirements, steps for installing and uninstalling, and installation troubleshooting information.

User Guide for Resource Manager Essentials — Provides information on using RME 4.0.5.

User Guide for Common Services — Provides information about setting up, administering, and accessing CiscoWorks Common Services 3.0.5

Resource Manager Essentials Online help— Provides task-oriented and context-sensitive help from every window that contains a Help button.

Also contains all of the information available in User Guide for Resource Manager Essentials. This ensures you have complete information even if you do not have the manual readily available while using RME.

For more details on the new features in RME 4.0.5, and the procedures mentioned in this document, see the User Guide for Resource Manager Essentials.

Additional Information Online

For information about RME supported devices, refer to the following URL:

http://www.cisco.com/en/US/products/sw/cscowork/ps2073/products_device_support_tables_list.html


Tip For the latest technical tips, suggestions for troubleshooting common issues, and frequently asked questions (FAQs) on most RME applications, you can:
Login to Cisco.com and select Products and Services > Network Management > CiscoWorks LAN Management Solution > CiscoWorks Resource Manager Essentials > Product Literature.


Service Pack (SP) for RME 4.0.5 is a collection of updated files necessary for RME to support new Cisco devices. In addition to the devices supported, this package also contains fixes to known problems, as well as additional newly discovered problems.

If you are a registered user, you can download the latest version of SP for RME 4.0.5 from:

http://www.cisco.com/pcgi-bin/tablebuild.pl/cw2000-rme

Caveats

The following are some caveats:

Before installing RME, ensure that you do not have CWSI Campus 2.x or Cisco Voice Manager on the system.

Before upgrading RME, ensure that all applications are stopped. The upgrade depends on having reasonable interaction time with the database. If this is not possible, the upgrade fails.

Browsers running on remote X servers are not supported in RME.

Known Problems in RME 4.0.5

This section contains known problems for RME 4.0.5:

Installation and Upgrade Known Problems

Administrator Known Problems

Device Management Known Problems

Device/Agent Known Problems Impacting ANI Server and RME Functionality

Inventory Known Problems

Archive Management Known Problems

NetConfig Known Problems

Config Editor Known Problems

Netshow Known Problems

Software Management Known Problems

Change Audit Known Problems

Syslog Known Problems

cwcli export Known Problems

Contract Connection Known Problems

Bug Toolkit Known Problems

Server, Browser, UI, and Desktop Known Problems

Common/Other Known Problems

For more information about known problems:


Step 1 Go to http://www.cisco.com

Step 2 Select Technical Support & Documentation > Tools & Resources.

Step 3 Select the Software sub-section and click Bug Toolkit.


Alternatively, go to: http://www.cisco.com/pcgi-bin/Support/Bugtool/home.pl

You will be prompted to log into Cisco.com.


Installation and Upgrade Known Problems

Table 1 Installation and Upgrade Known Problems 

Bug ID
Summary
Explanation

CSCsc46237

Restore fails even when there is adequate space

RME restore operation fails with an insufficient disk space error.

While restoring, the backup data is extracted in the partition where the backup exists. Therefore, if the partition does not have enough space, the insufficient disk space error appears.

Workaround:

Either increase the partition space or copy the backup to a different partition that has enough space.

CSCsa15596

RME installation quits unexpectedly.

Errors such as

String variable is not large enough for the String

appear during the installation of Common Services.

This is because NMSROOT (CiscoWorks Install directory) has a very long pathname.

During Common Services installation there is no restriction imposed on the installation directory path length.

Owing to this, Common Services installation might not fail, if the string length is less than 1024.

However, in the case of RME the chances of failures are high because, RME has longer classpaths which are close to 950 characters with NMSROOT length = 39 characters.

Workaround:

Do not to use a long pathname for NMSROOT (CiscoWorks Install directory).

CSCsa33360

Device groups migrated for users (Approvers and Network Operators) cannot be edited by users with the same roles in RME 4.0

Users with Approver and Network Operator roles cannot edit or delete device groups in RME 4.0 that were created in RME 3.x by users with the same roles.

This happens when the device groups created in RME 3.x by users with Approver and Network Operator roles, are migrated to RME 4.0.

Workaround:

None.

CSCsa33365

Network Administrator cannot edit or delete device groups in RME 4.0 that they created in RME 3.x, after migration.

After migration from RME 3.x to RME 4.0, a user with a Network Administrator role cannot edit/delete groups in RME 4.0 that the user created in RME 3.x.

This happens when the device groups created in RME 3.x by a user with a Network Administrator role, are migrated to RME 4.0.

Workaround:

None.

CSCsa34359

Change Audit details are not available for some of the NetConfig records after data migration from RME 3.x to
RME 4.0.

The change details cannot be identified for some of the NetConfig records.

This is because you have purged configuration files in the RME 3.x server where the backup was taken for migration.

These purged configuration files are not available in RME 4.0 server after data migration. An error appears, Internal Error: Config File information not available.

Workaround:

None.

CSCsa45325

No able to upgrade fromRME 3.4 to RME 4.0 when HPOV is running.

This is because during upgrade some of the dll files are locked in this directory, NMSROOT\objects\smarts\bin

Where NMSROOT, is the CiscoWorks installed directory.

Workaround:

Stop the HPOV process while upgrading to RME 4.0.

CSCsa22623

Data inconsistency on restoring data backed up with jobs in running state.

After restoring RME 4.0 data on a system, the job status is not the same as that of the system where the backup was taken.

When a backup is triggered while a job is running, the Restore command is not aware of the state of the jobs in the backed-up machine.

Additionally, the Backup/Restore command does not backup/restore the state of the systems. It is only the data that is backed-up and restored.

Workaround:

Ensure that while backing up data, there are no jobs running on the system.

CSCsd41732

RMEDbEngine Process Entries not found after upgrading RME 4.0.3 to RME 4.0.4/ RME 4.0.5

When you install RME 4.0.3 and upgrade to RME 4.0.4 / RME 4.0.5, the RMEDbEngine entries do not appear in the registry.

Workaround:

None.

CSCsd66695

Bug Tool Kit summary Report Jobs not shown in Report Archive.

When you backup data from RME 4.0 / 4.0.1 / 4.0.2 and restore it to RME 4.0.3, the Bug Tool Kit summary report jobs are not displayed in Reports Archive.

Workaround:

Change the path value of CriArchiveLoc in regdaemon.xml to point to NMSROOT.


Administrator Known Problems

Table 2 Administrator Known Problems 

Bug ID
Summary
Explanation

None

Some of the RME processes are suspended.

If you start RME entering

net start crmdmgtd

make sure you do not suspend the session with the suspend command.

If you suspend the root session after manually starting RME, other processes, such as Daemon Manager, and ICServer, are also suspended.

Workaround:

Resume the suspended session.


Device Management Known Problems

Table 3 Device Management Known Problems 

Bug ID
Summary
Explanation

CSCsa18790

Device moves from Pending to Normal to Conflicting state

During device import, devices may appear as Normal Devices for a very short span of time but later on move to Conflicting or Alias states after Conflict detection or Alias detection, respectively.

This may occur when you add a large number of duplicate or conflicting devices.

Workaround:

Wait for all devices to be processed for management. This may take some time depending on the number of devices added.

CSCsa22830

DLMS fails in SSL mode

This happens when you get or set credentials using DLMS in SSL mode.

Workaround:

SSL support for DLMS is not available in RME 4.0 and therefore there is no workaround.

CSCed47422

Device Management State Summary show wrong record count.

A label on right top of Device Management State Summary screen shows, for example:

Showing 7 records

This problem occurs because of the default display provided by the underlying UI component (HTML Scrolling table).

Workaround:

This caption should be read as the number of records displayed on that screen — not the number of devices or the number of device states.

CSCsa36278

AUS should not be displayed in the Picker list while adding devices to RME.

Auto Update Servers (AUS) appear in the Add Devices screen.

This happens when you add new devices into RME, and PIX devices managed by Auto Update Servers are also a part of the list of devices to be managed in RME.

Workaround:

If Auto Management option is enabled, delete Auto Update Servers after they are added to the Normal Devices list.

If you select devices from the Add Devices screen filter out these Auto Update Servers.

CSCsa45574

Alias detection fails for some devices.

Alias detection does not work for devices that are accessed using a virtual management IP address.

This happens when you add devices with virtual management IP address.

Workaround:

Manually resolve aliases by deleting duplicate entries from the Normal Devices dialog box.

See the User Guide for Resource Manager Essentials for details.

CSCsa52951

Device Credential Verification does not run when device moves from conflicting to normal state

Device Credential Verification is not triggered when a device moves from Conflicting to Normal state.

This happens when the device type conflict is resolved and the device moves to Normal state.

Workaround:

Manually trigger Device Credential Verification for such devices.


Device/Agent Known Problems Impacting ANI Server and RME Functionality

Table 4 Device /Agent Known Problems Impacting ANI Server and RME Functionality 

Bug ID
Summary
Explanation

CSCsa39153

Archive Management tasks fail for Catalyst 4507 device.

Archive Management tasks fail for Catalyst 4507 device, if you have selected TFTP as the transport protocol.

The happens because of incorrect implementation on the device.

Workaround:

Select a different transport protocol using Resource Manager Essentials > Admin >
Config Mgmt.

See Supported Device Table for Archive Management Application on Cisco.com for supported transport protocols information for the Archive Management application:

http://www.cisco.com/en/US/products/sw/cscowork/ps2073/products_device_support_tables_list.html

CSCsa19145

SSH connection to the device fails because of SSH disconnection packet.

This problem occurs in a slow network when RME tries to contact device using SSH connection.

This happens because of incorrect implementation of SSH daemon (sshd) on the device.

Workaround:

None.

CSCsa44813

Archive Management tasks on startup configuration using TFTP does not work

Archive Management tasks on startup configuration using TFTP protocol does not work.

This happens because the device supports only OLD-CISCO-CONFIG-MIB for TFTP and this MIB does not support tasks on startup configuration.

Workaround:

Select a different transport protocol using Resource Manager Essentials > Admin >
Config Mgmt.

See Supported Device Table for Archive Management Application on Cisco.com for supported transport protocols information for the Archive Management application:

http://www.cisco.com/en/US/products/sw/cscowork/ps2073/products_device_support_tables_list.html

CSCsa40523

Chassis slot incorrect for MDS 9509

MDS device with software version 1.3(4a) renders incorrect values for its chassis number of slots.

This problem is identified in software version 1.3(4a).

Workaround:

Install software version 2.0(1).

CSCed88554

Supervisor software version value is 0

Device does not return Supervisor software version.

This happens when the device is configured with SNMP.

Workaround:

None.

CSCsa07154

Cannot query containment AG for Catalyst 5000 devices.

If the device happens to run with Cisco Catalyst Operating System Software, Version 4.5(13a), then it is likely that SNMP query fails for numSlots (SysObjectID > "1.3.6.1.4.1.9.5.1.3.1.1.25").

This happens when the device is configured with SNMP. The problem occurs because support in the Catalyst OS fails for this SysObjectID.

Workaround:

None.

CSCsa36845

Processor Port and Module Port section are missing from DDR for 4506 IOS

The device running IOS,Version 12.1(22)E2 fails for correlation between the port and the interface because ifIndex is rendered Null.

This happens when the device is configured for SNMP.

Workaround:

The problem does not occur with the IOS, Version 12.1(9a). Upgrade the device to this version.

CSCsa28210

cwcli export for CSS 11800 information is missing

Software Identity is missing in cwcli export, in the case of CSS 11800.

This happens when the CSS 11800 device has to be SNMP configured. The device does not return the processor component, while queried using SNMP.

Workaround:

None.


Inventory Known Problems

Table 5 Inventory Known Problems 

Bug ID
Summary
Explanation

CSCsb28200

Grouping rules that are built using equality matches on :RME:INVENTORY:Device.System.SystemOID do not find matches.

This happens if the sysObjectID on which the match is performed does not begin with a leading dot.

All sysObjectIDs in RME are stored with a leading dot.

Workaround:

Either specify the leading dot in the match value, or change the operator from Equals to EndsWith or Contains.

CSCsc31440

RME detailed device report shows incorrect serial number for Cat2950

RME reports incorrect serial number information in detailed device reports for the Catalyst 2950 switches.

This is because RME polls chassisId in OLD-CISCO-CHASSIS-MIB.

However, the serial number information is available in entPhysicalSerialNum of the ENTITY-MIB which is what RME should use.

Workaround:

Hard code the chassis-id using the CLI on the 2950:

conf t

snmp-server chassis-id the-real-serial-number

where the-real-serial-number is the Serial Number.

CSCsb40088

The Inventory > Hardware Report does not populate RAM, NVRAM, Used NVRAM fields for most CatOS switches RME 4.0.1

Inventory data is collected from StackMib. This does not have NVRamSize, RAM Size and Used NVRAM attributes.

These attributes need to be collected using EntityExtMIB or OCCM. However, the reports code is refers to EntityExtension MIB. Hence, these fields appear blank.

Workaround:

None

CSCsa86823

A device in the normal state appears with ? icon and cannot be selected.

The Device Selector shows ? as the icon for a normal device for which configuration collection is successful.

Device and Credential Repository (DCR) did not have the device type information while the device was added.

Inventory collection failed because of SNMP time-out.

Workaround:

Update the device type information in DCR.

Make sure that the inventory collection succeeds (if required, increase the SNMP time-out value).

Note SNMP timeout exceptions can be seen in IC_server.log.

For details on editing device information in DCR, increasing SNMP time-out values, etc., see the User Guide for Resource Manager Essentials or the RME 4.0.3 Online help.

None

Desktop machines appear incorrectly.

Do not import desktop machines unless they are running Cisco Call Manager applications. Otherwise, desktop machines appear incorrectly in the device selector under Call Managers.

Workaround:

None

None

IP addresses of cable modems ubr904 and ubr924 may change between reboots.

These devices get the IP address of the cable interface using DHCP from head-end cable router. The IP address might change between reboots.

Workaround:

You must import cable modems ubr904 and ubr924 using fully qualified pathnames.

None

Cannot manage PIX Firewall device without RME server IP address.

PIX Firewall device cannot be managed in RME without the IP address of the RME server.

Workaround:

1. Configure the PIX Firewall device so that it can be managed.

2. Enter the IP address of the RME server.

None

Check Device Attributes fails for devices that are already managed through the host name.

This happens when the IP address of the device host name is changed on the DNS server or on the local hosts file (/etc/hosts).

Workaround:

Restart the Daemon Manager.

CSCsa36663

Location of archived reports cannot be changed.

All reporting application archives are stored at a predefined location and you are not given an option to change it.

After the disk is full with archived files, further jobs fail.

Workaround:

None.

CSCsa36932

The Inventory Job Status page shows deleted device information.

When a device is deleted, the associated change records are deleted, but the device is still a part of the scheduled jobs.

Hence, the job browser shows the status of the job as:

Successful: With Changes

However, when you click View Details, a message appears:

No changes

for a job that has already run. This is because the changes have already been deleted.

Workaround:

None.

CSCsa38526

RAM, NVRAM information duplicated for some multi-processor devices

In the Processor Information section of the Detailed Device Report, Processor details such as RAM and NVRAM information are duplicated for some multi-processor devices.

This happens when the multi-processor devices do not have support for CISCO-ENTITY-EXT-MIB.

Workaround:

None.

CSCsa16772

Cannot create a Private Custom Template with the same name for different users.

If a template with the name ABC, is created by user X, with any access type, then user Y cannot create a template with the same name ABC.

However, user Y cannot see the template named ABC, which user X has created with private access. This may confuse user Y.

Workaround:

Use the following CLI command to view all template names (Private and Public access):

cwcli invreport -u username -p password -listreports.

This will display all the templates defined in the system. Also, avoid template names that are already in use.

CSCsa22899

Device Credential Verification reports no value to test for Enable when Telnet password is blank

If you do not enter the Telnet Username and Password and only enter the Enable Password, Device Credential Verification reports DID NOT TRY for its the Enable Password check.

The condition under which this problem occurs is that both Telnet Username and Password are not provided in Device and Credential Repository.

Workaround:

None.

CSCsd65609

Scheduled Inventory Collection and Polling jobs are not displayed.

Scheduled System Inventory Collection or System Inventory Polling jobs are not shown in the Inventory job browser or in the RME Job Browser.

Workaround:

View these details from Common Services Job browser or using the RME > Admin > Inventory > System Job Schedule screen.

CSCsc22924

CDA fails for a device configured with TACACS prompt.

This problem occurs when the Telnet credentials are incorrect. CDA fails although you have entered the correct credentials and Sync Archive applications are successful.

Workaround:

None.

CSCsd65650

Incorrect device status count when using ACS in RME 4.0.3 Device Manager.

When LMS 2.5.x is integrated with ACS, the count of managed devices under Device Management and Device Selector are not the same.

This is because some devices in Device Credential Repository are not registered as clients of ACS.

Workaround:

None.

CSCse06499

Inventory MSP report status shows Success for non MSP capable devices.

When an Inventory Multi-service Port (MSP) report is scheduled for non-MSP capable devices, the job status is displayed as Successful.

Workaround:

None.

CSCsb74173

Job details not shown for Inventory report jobs migrated from RME 4.0 to RME 4.0.x

When Inventory report jobs are migrated from RME 4.0 to RME 4.0.x, the job output is displayed in the target machine but not the the job details.

Instead, the following error message is displayed:

Job not found, Please see the log for more 
details

Workaround:

None.

CSCse13013

Inventory collection jobs take more time to run.

When an Inventory Collection job is scheduled from RME > Devices > Inventory > Inventory Jobs the scheduled job, remains in a running state for a long time,

This occurs even if it is scheduled for a single device. The Inventory Collection Job Details page for this job shows the Scanned field as 0 for a long time.

Workaround:

None.

CSCse03788

Audit Trail report for deleted devices not proper

Audit Trail report for deleted devices does not display the identity entered when you added the devices. Instead it displays:

Device with Identity UNKNOWN Deleted

in the Description field.

Workaround:

None.

CSCse26973

NVRAM and Total RAM information missing in Hardware Report for IGESM device.

The IGESM device does not consist of NVRAM and Total RAM details. So when you generate a Hardware report for this device, the NVRAM and Total RAM details do not appear in the report.

Workaround:

None.


Archive Management Known Problems

Table 6 Archive Management Known Problems 

Bug ID
Summary
Explanation

None

Banner commands containing (") and (^C) characters cause configuration applications to function incorrectly.

If banner values are contained between quotation marks (") in Config Archive and between Ctrl-C (^C) characters in a device, the configuration applications do not function correctly.

Workaround:

Do not add Ctrl-C characters to the banner commands while downloading them to the device.

None

Module configuration is not retrieved even if the module has valid credentials for a CAT switch.

Configurations of IP addressable modules are not retrieved along with Supervisor even if the module has same credentials as the Catalyst switch.

IP addressable modules should be managed as a separate device.

Configurations of non-IP addressable modules are fetched along with Supervisor configuration only if the selected protocols are Telnet or SSH, provided the module has same credentials with Supervisor. Other protocols are not supported.

Workaround:

None.

CSCsa97886

Config deploy in the Merge-mode download fails in C2970G-24T-E because of Certificate

Configuration deployment in the Merge mode fails for C2970G-24T-E when you try to deploy certificate commands.

This is because:

The configuration that you are trying to deploy has certificate configuration, which is fetched from the running configuration.

and

The configuration archived from the running configuration has certificate commands with the private keys missing.

Workaround:

Make sure that the configuration you are deploying has the certificate commands properly configured (including the private keys).

If you want to deploy non-certificate commands from the configuration, remove all certificate-related commands from the configuration.

CSCsa85666

WLAN Module: Sync Archive fails when TFTP is used.

The Sync Archive operation fails for the WLAN module when TFTP is the only transport protocol that is used.

TFTP is not supported since Config-Copy-MIB is not supported by this device.

Workaround:

You can do a configuration Fetch operation using Telnet and SSH.

Enable these protocols in the Config Transport Settings page (Resource Manager Essentials > Admin > Config Mgmt) and then trigger the configuration collection.

For details, see the User Guide for Resource Manager Essentials or the RME 4.0 SP1 Online help.

CSCsa55997

Sync Archive Fails for few NAM devices

Sync archive of NAM devices fails.

If the previous deploy job failed with a timeout exception, subsequent sync archive jobs for that NAM device will fail.

Workaround:

Either:

Stop and restart the ConfigMgmtServer service at Common services > Server > Admin > Processes.

Make sure that no other jobs are running. If they are running, perform this task operation after the jobs complete.

Or

For the specific device, fetch the startup or running configuration using the Startup or Running hyperlinks respectively at Resource Manager Essentials > Config Mgmt > Archive Mgmt > Version Summary.

CSCsa44963

Archival fails in Cisco Content Services Switch 11050.

Configuration archival fails in the Quick Configuration deployment job in the Merge mode for Cisco Content Services Switch 11050.

Workaround:

None.

CSCsa37473

Issue in Config for device CSS 11050

Archived configuration does not contain the complete running configuration.

This occurs happens when the image on the device is Content Switch SW Version 5.02 Build 3 with SNMPv1/v2c Agent.

This happens when configuration fetch is tried with both Telnet and TFTP protocols.

Workaround:

None.

CSCsa35699

VPN configs coloring scheme is incorrect for Compare Configs.

In the Config Diff Viewer, the diffs of modified commands are shown in blue text instead of red.

For VPN 3000 devices, the diff viewer shows the modified commands in blue instead of red, as in other devices.

Workaround:

None.

CSCsa35538

Configuration archival fails for VPN devices.

On Windows, the configuration fetch operation for VPN 3000 devices, fails.

This happens when there are characters such as '<,''>' in the configuration file. For XML parsers these characters are the delimiters.

Workaround:

Remove these characters from the configuration file.

CSCse38902

SSH connection times out while contacting a device over a wireless network.

When you try to establish SSH connection using wireless network to contact a device, the connection times out.

Workaround:

None

CSCse88215

Change Audit Purge job does not remove diff files

Change Audit Purge job does not remove diff files even after the corresponding config versions are removed.

Diff files are files that are created as Change Audit reference records during the Archive Purge.

Workaround:

Manually remove diff files from the diff files directory :

NMSROOT\files\rme\dcma\

CSCse34985

TFTP deploy fails for CAT7K device.

While deploying configurations using TFTP protocol for a Cat7K device, the deployment fails. This failure occurs only on a Windows platform.

Workaround:

None.


NetConfig Known Problems

Table 7 NetConfig Known Problems 

Bug ID
Summary
Explanation

CSCsa78026

Adhoc Enable Mode command, sh run fails for some string patterns

When you create a NetConfig Job with the Adhoc Enable Mode Command sh run, the job status may be reported as Failed even if the commands have been successfully downloaded.

This may occur when the successfully downloaded command output contains well-known error messages such as ERROR:, %ERROR: etc., (which are ideally a part of the command output during error conditions only).

Workaround:

None.

CSCsa88829

Issue with credentials removal in DCR with NetConfig job, when AAA new-model is enabled

When you are disabling credentials using NetConfig, the device may become unreachable from within RME.

However the device remains reachable outside RME.

This may occur when you disable or remove credentials such as Telnet password using a system-defined task in NetConfig.

Workaround:

To enable TACACS authentication, you should use the TACACS+ task and not the Telnet Password task.

To disable one kind of authentication, you should enable another kind of authentication.

For example, if you want to disable Telnet authentication and enable TACACS+ authentication, you can simply enable TACACS + authentication.

CSCsa15482

Network Time Protocol template does not generate proper rollback commands.

When the download command fails on a device, the successfully downloaded commands are rolled back, if the Rollback policy is on.

If the command ntp authentication-key is already present in the device and if you attempt a rollback of the command, it fails.

Workaround:

None.

CSCsa16093

Trap notifications fail for certain image features.

For Cisco IOS devices, if you select certain trap notifications types for the snmp-server host command in the traps template, it might lead to command download failure.

Workaround:

None.

CSCsa19184

Rollback for the SSH key bit configuration command does not restore the original number of key bits.

This happens when you have enabled SSH on a device with a certain number of key bits and then enable or disable the key bits through an SSH template download.

The download of commands other than the key bits command, fails.

Workaround:

None.

CSCsa22697

Rollback for the ntp server command does not restore the original command on the device.

This happens when you have an ntp server command on the device with the key option enabled.

If you change the command on the device through an NTP template download, the download of all other command fails.

Workaround:

None.

CSCsa24300

Authentication method of non-ip addressable sub-modules is not updated.

When you update the authentication method for the Supervisor module using the tacacs+ template, it does not update the authentication method.

It also does not update the passwords of the non-ip addressable sub-modules.

Workaround:

1. Add a Telnet or Enable password template and apply commands with the same password to the modules.

2. Add a tacacs+ template to update the authentication method for the Supervisor module. Use the same password as above for this template.

CSCsa25755

Rollback of a job changes the password on the device.

This happens when you rollback a job containing two credential templates. When you change the Enable password, it might change the password on the device.

For example, RADIUS and enable or Tacacs+ and enable.

Workaround:

Do not have two different templates changing the Enable password credentials in the same job.

CSCsa27946

CSS: NTP: Server IP address alone allowed. Download fails for hostname

While configuring SNTP server, the IP Address of the SNTP server has to be specified. Instead of the IP Address, if SNTP server hostname is specified, the template fails.

This is applicable for all versions from 5.0 onwards.

Workaround:

Specify the IP Address of SNTP server instead of the SNTP server hostname.

CSCsa44983

The commands fails only for Content engine devices running ACNS 5.2 or later versions.

This happens when the commands deployed using Syslog task on Content Engine devices fails for logging priority configuration.

Workaround:

Do not configure logging priority using Syslog system defined task on Content Engine devices running ACNS version 5.2 or later.

1. Create a user-defined task for configuring logging priority with commands specific to ACNS 5.2 or later

2. Use that for deploying on Content Engine devices running ACNS 5.2 or later.

CSCsa44626

IOS-enable TACACS fails when aaa new-model is enabled.

Download of TACACS commands such as login tacacs, tacacs server etc., fail.

This happens when the command, aaa new model is present on the device.

Workaround:

Disable the aaa new model command. To do this use either the TACACS+ or RADIUS template before adding the TACACS template commands.

CSCsa23231

Job Creation wizard loses context when multiple templates are opened.

This problem occurs while creating a NetConfig job, in the second step of the wizard (Add Tasks).

If you open multiple task windows simultaneously and try to add the tasks to the job, there are problems with the wizard.

Workaround:

Open only one window at a time.


Config Editor Known Problems

Table 8 Config Editor Known Problems 

Bug ID
Summary
Explanation

CSCsb78495

Config Editor overwrite job does not work for PIX devices

A Config Editor job in the overwrite mode, does not work for PIX devices. That is, when you are deploying a configuration that you have edited using Config Editor, to a PIX device, in the overwrite mode, the deployment is unsuccessful.

This happens if you:

1. Edit the configuration of a device using Config Editor and save it.

2. Create a job to deploy that configuration to a PIX device, using the Overwrite mode.

The job fails.

However, the job, succeeds in the Merge mode

Workaround:

None.

CSCsa36347

SNMP Authentication/privacy passwords not masked in device response

SNMP security password and Privacy passwords appear in an argument list in the Device Details page.

This happens when Debug is enabled in the device.

Workaround:

Disable Debug on the device.

CSCsa39790

Config Editor updates the Device and Credential Repository with an encrypted string.

If service password-encryption is enabled on the device then credential would be encrypted in show config output of the device.

The Device and Credential Repository is updated with this encrypted password, if you:

1. Create a Config Editor job in Merge mode using Telnet as the transport protocol.

2. Deploy this command using the Config Editor application.

Workaround:

Use the NetConfig application to update the encrypted credential command.


Netshow Known Problems

Table 9 Netshow Known Problems 

Bug ID
Summary
Explanation

CSCsb43125

RME database does not update the CommandSet details after migration

RME database does not update the CommandSet details after migration

This is caused by the character '+' in the Command Set name RME3.4+IDU11.0. NetShow in RME 4.0.x UI does not allow this character.

Workaround:

Before taking a backup in RME3.x, make sure that none of the CommandSet names have special characters.

CSCsa86905

Custom commands, that are not assigned to any Command Sets, are not migrated

This occurs if:

1. In RME 3.x, in NetShow, you had a few isolated custom commands that were not associated with any command set.

2. You backed up and migrated these custom command sets into RME 4.0 SP1.

These isolated custom commands do not exist in RME 4.0 SP1 NetShow after migration.

Workaround:

You can associate these isolated custom commands with any user-defined command set in RME 3.x, before taking a backup. Then these custom commands will be migrated as if they were a part of a command set.

CSCsa73709

Cannot remove an Adhoc command from the Available Commands list

You may not be able to delete an Adhoc command from the Available Commands list (in the Select Commands page of the Resource Manager Essentials > Tools > NetShow > Command Sets flow) even if it is in only one command set.

This occurs in this scenario when you want to remove an adhoc command:

1. In the Resource Manager Essentials > Tools > NetShow > Command Sets flow and from the Command Sets page, select the command set you want to edit and click Edit.

The Select Device Category Page appears.

2. Click Next.

3. Select the ad hoc command that you want to delete, from the Selected Commands list and click Remove.

The command moves to the Available Commands list.

4. Select the command from the Available Commands list and click Delete Adhoc.

You will see an error:

NS0011 :The command(s) show run are not deleted because they may be system-defined or part of a command set or in the selected commands list.

The Adhoc command is not deleted.

5. Select the command from the Available Commands list and click Delete Adhoc.

You will see a message that the command is successfully deleted.

CSCsb09234

OutOfMemory exception on printing job output

A 500 server error appears with an out-of-memory exception when you print NetShow Job Results.

This may occur when the job has more than 1500 devices and has a high number of commands that produce voluminous output.

Workaround:

Use the Per-device Print option.

Increase the Tomcat heap-size.

Reduce the number of devices in the job.

CSCsa75907

Cannot add Adhoc commands that are device-specific, in the same command set.

You cannot add device type-specific Adhoc commands in the same command set. The Adhoc commands that you have added in a specific command set apply to all the device types that you have selected.

This scenario occurs when, in the command set creation flow of NetShow (Resource Manager Essentials > Tools > NetShow > Command Sets), you:

1. Choose device categories

2. Add Adhoc commands.

3. Complete the flow.

These Adhoc commands will be applicable to all the device types that you have selected.

For example, if you choose device types Content Networking and Router and add an Adhoc command, this command will be applicable to both Content Networking and Router device types.

Workaround:

Create different command sets for different device types.

For details on creating command sets, see User Guide for Resource Manager Essentials, or the RME 4.0.3 Online help


Software Management Known Problems

Table 10 Software Management Known Problems 

Bug ID
Summary
Explanation

CSCsb68458

Software Management fails on Catalyst 5500 with an error

An error, SWIM1035, appears when you try to distribute new software to Catalyst 5500

This occurs:

When RME 4.0 (or later) is installed.

When the device is Catalyst 550x with Supervisor III (WS-X5530)

The content of the error message is :

SWIM1035: Error while performing Recommendation operation.

Runtime error encountered while filtering images caused by a problem with a running image on the device.

See the Troubleshooting section of the RME 4.0 help.

Workaround:

None.

CSCsb42968

RME 4.0 does not distribute images to Cisco Catalyst 6500 series devices running CAT OS.

This problem occurs when the image is being copied to:

1. bootflash: using TFTP or RCP.

2. Slot0: using RCP only.

Workaround:

Use Slot0: with TFTP for distribution.

CSCsb19581

rcp does not work for Windows 2003 Server

Image transfer using rcp protocol fails in Windows 2003.

This happens when CiscoWorks is installed on Windows 2003.

Workaround:

1. Give full permissions for the casusers group to execute cmd.exe.

2. Retry the image transfer.

None

Cannot undo image upgrade of tar images for DSBU switches.

After performing an image upgrade of tar images for DSBU switches, you cannot undo the job.

Workaround:

Select the tar image and schedule a new distribution job.

CSCin19501

Software Management includes the bootflash of MSFC as a storage option.

This happens for Cat6000 supervisors running IOS.

Storing the IOS images in the bootflash might bring the device down.

Workaround:

Do not select the bootflash to store the image while upgrading Cat6000 devices running IOS.

Select a different storage location.

CSCsa29037

Image upgrade using Remote Stage fails if the image size exceeds 32 MB.

In the Remote-Stage flow, the only protocol that is supported currently between Remote Stage device and target device, is TFTP.

Here, it uses the TFTP server of IOS on the RS device.

There is a limitation in the Cisco IOS TFTP server for transferring files exceeding 32MB from Remote Stage device to Target device.

Workaround:

Upgrade the IOS image to any of the following versions which has the 32 MB fix:

12.2(18)SXE

12.003(009.008)

12.0(29.03)S

12.2(17d)SXB07

12.2(18)SXD04 12.2(25.04)S

12.3(09.08)T

CSCsa32595

Software Management distribution fails for all devices running Cisco IOS Release 12.3(5x).

This happens because CISCO-FLASH-MIB returns the Flash partition name as Flas instead of Flash.

This problem is found in all devices running Cisco IOS Release 12.3(5x).

Workaround:

None.

CSCsa33864

Add Image or distribution fails in Software Management.

If the tftpboot directory is either a symbolic link or a soft link to a different directory, Software Management add image or distribution operations fails.

Workaround:

None.

CSCsa35853

Software Management Add Image from device and Image Distribution flows fail.

This happens when there are a large number of Cisco Catalyst 2900XL and 3500XL Series Switches selected in the workflow.

These devices will be in pre-deployed state or might have invalid Telnet credentials in the Device Credential Repository.

The application attempts to connect to the device to obtain Flash device and image file information.

Workaround:

We recommend that you do not include a large number of pre-deployed Cisco Catalyst 2900XL and 3500XL Series Switches in the workflow.

CSCsa32962

Device reboot fails when upgraded or downgraded to images with Cisco IOS Release12.2(14)SY*.

The device goes into ROMMMON mode.

This happens when the device is upgraded or downgraded to 12.2(14)SY* versions, that is, 12.2(14)SY4, 12.2(14)SY6.

However, Software Management operations cannot be performed after the upgrade, since the CISCO-Flash-Mib is broken.

Workaround:

If you have 12.2(14)SY* images, upgrade to a higher version available on Cisco.com.

If you have to upgrade or downgrade to these versions, do not select Reboot Immediately in the Software Management Job Options window.

Reboot the device manually.

CSCsa36324

Expert Flow does not work for Cisco Catalyst 3750 Switch.

All Software Management flows except Expert Flow are working for Cisco Catalyst 3750 Switch.

This problem occurs because the image version on this device does not have proper Flash instrumentation.

Workaround:

None.

CSCsa37036

copyFromFlash on Aironet device always returns success even when there are no files on Flash.

This problem is seen in all Aironet devices. These devices do not have proper Flash instrumentation.

Workaround:

None.

CSCsa47065

7300—Image size verification fails after copy, with running img ver 12.2(18)S

Software upgrade verification fails for a 7300 device if the device is running 12.2(18)S version or any other version in which CISCO-FLASH-MIB does not give ciscoFlashFileName correctly.

In 12.2(18)S, ciscoFlashFileName is returned as disk0 for the image in disk0.

Workaround:

Upgrade the device manually to a different IOS version, in which this problem with ciscoFlashFileName is resolved.

CSCsa22845

Catalyst 5000—Discrepancy in Image Import from Device and Add Image from Network

Image import from the network is not supported for Catalyst 5000.

Workaround:

None.

CSCsa39312

C10700: Distribution fails because of too many boot commands

If there are too many valid boot commands in the device startup-config, the boot command for the new image will not get added to device bootvar.

This happens during device upgrade using Software Management.

If you select the Reboot option because of this, the device is rebooted but it does not boot with the new image.

This happens only if many valid boot commands exists on the device before upgrade through Software Management.

Workaround:

Remove some boot commands from startup-config before trying the Software Management job.

CSCin50067

CE: Reboot verification fails when comparing the image version

Reboot verification may fail when images with version prior to 5.1.x, are distributed to Content Engine devices. As a result, Software Management distribution jobs show the status as Failed although the job is successful.

Content Engine devices running ACNS 5.1 or lower, may not return a string that indicates the build number of the software release.

For example, ACNS 5.1.3b17 will be returned in ceAssetSoftwareRevision as 5.1.3.

Workaround:

Manually check the reload.

CSCsc30476

Image cannot distribute for VPN devices that do not have Rel as a substring.

SWIM cannot distribute the images to VPN devices, if sysDescr does not have Rel as a substring.

Workaround:

None.

CSCsd39567

In Image version, SWIM cannot parse for FWSM.

If you are distributing FWSM 3.1 images, they fail while identifying the version and display a parsing error.

Example: c6svc-fwm-k9.3-1-1.bin

Workaround:

None.

CSCsd58156

3750 tar images not transferred while using SCP in RME 4.0.x SWIM.

When a 3750 tar image is distributed using SCP as transfer protocol (instead of RCP or Telnet), the tar image is not uncompressed. Owing to this, the switch does not boot.

Workaround:

Use RCP as the transfer protocol.

CSCsd68468

Dual supervisors not supported by SWIM.

SWIM does not identify dual supervisors on Cat6K switches running CatIOS, and so does not perform a redundant upgrade.

Workaround:

None.

CSCse00974

SWIM uses HOSTNAME instead of IP address for TFTP (RME) destination.

This happens when the device and RME server both are inside the NAT boundary and the public IP address for the device is configured in RME server.