简介
本文档介绍有助于确定和纠正思科安全邮件网关与URL追溯服务之间的通信问题的信息和故障排除步骤。
背景
内部服务(称为注册客户端)负责保持服务证书最新。但是,在某些网络情况下,此过程可能会变得无响应并停止重试尝试。这可能会导致无法及时收到更新后的证书,从而导致服务中断。
注意:思科TAC强烈建议运行AsyncOS版本15.0及更高版本的所有客户主动运行ecupdate命令(如本文所述),以解决和预防此潜在问题。
使用的组件
本文档不限于特定的软件和硬件版本。
本文档中的信息都是基于特定实验室环境中的设备编写的。本文档中使用的所有设备最初均采用原始(默认)配置。如果您的网络处于活动状态,请确保您了解所有命令的潜在影响。
症状
系统生成以下警报:
20 May 2025 07:37:04 +0700 Connection to URL Retrospective registration service failed. Certificate verification failed. Contact Cisco TAC for assistance.
这些警报将发送到已配置的邮件地址。如果某个电子邮件地址尚未与警报相关联,则可以通过导航到系统管理 >> 警报并单击查看排名靠前的警报或运行displayalerts CLI命令来检查这些地址。
可以在ecs日志中找到以下错误:
esa01.example.com> grep "Warning|Critical" ecs
Fri May 16 18:57:05 2025 Warning: ECS: Cloud query failed. 'Empty polling URI.' 7-xyxxyzxyxxyz (or b'xyxxyzxyxxyzxyxxyzxyxx==' in base64 format) having URLs. Contact Cisco TAC for assistance.
Fri May 16 18:57:31 2025 Critical: ECS: Failed to regenerate token. Status Code: 403. Invalid Certificate.
解决方法
要解决此问题,请建立到设备的SSH连接并运行ecupdate force:
esa01.example.com> ecupdate force
Requesting forced update of Enrollment Client.
要验证注册客户端的更新是否成功,请监控updater_logs和ecs日志:
esa01.example.com> tail updater_logs
Tue May 20 11:26:19 2025 Info: Received remote command to signal a manual update
Tue May 20 11:26:51 2025 Info: Acquired server manifest, starting update 9030
Tue May 20 11:26:51 2025 Info: Server manifest specified an update for case
Tue May 20 11:26:52 2025 Info: Server manifest specified an update for enrollment_client
Tue May 20 11:26:52 2025 Info: enrollment_client was signalled to start a new update
Tue May 20 11:26:52 2025 Info: enrollment_client processing files from the server manifest
Tue May 20 11:26:52 2025 Info: enrollment_client started downloading files
Tue May 20 11:26:52 2025 Info: enrollment_client waiting on download lock
Tue May 20 11:26:52 2025 Info: enrollment_client acquired download lock
Tue May 20 11:26:52 2025 Info: enrollment_client beginning download of remote file "http://updates.ironport.com/enrollment_client/3.0/enrollment_client/default/109101"
Tue May 20 11:26:52 2025 Info: enrollment_client released download lock
Tue May 20 11:26:52 2025 Info: enrollment_client successfully downloaded file "enrollment_client/3.0/enrollment_client/default/109101"
Tue May 20 11:26:52 2025 Info: enrollment_client started applying files
Tue May 20 11:26:52 2025 Info: enrollment_client applying file "enrollment_client"
Tue May 20 11:26:52 2025 Info: enrollment_client installing new libexec
Tue May 20 11:26:52 2025 Info: enrollment_client restarting
Tue May 20 11:26:55 2025 Info: enrollment_client verifying applied files
Tue May 20 11:26:55 2025 Info: enrollment_client updating the client manifest
Tue May 20 11:26:55 2025 Info: enrollment_client update completed
Tue May 20 11:26:55 2025 Info: enrollment_client waiting for new updates
esa01.example.com> tail ecs
Tue May 20 09:05:21 2025 Info: ECS: Device registration successful.