簡介
本文檔介紹有助於識別和糾正Cisco安全電子郵件網關與URL追溯服務之間的通訊問題的資訊和故障排除步驟。
背景
內部服務(稱為註冊客戶端)負責保持服務證書最新。但是,在某些網路情況下,此進程可能會變得無響應並停止重試嘗試。這可能會導致無法及時收到更新的證書,從而導致服務中斷。
附註:Cisco TAC強烈建議運行AsyncOS 15.0版及更高版本的所有客戶主動運行ecupdate命令(如本文所述),以解決和防止此潛在問題。
採用元件
本文件所述內容不限於特定軟體和硬體版本。
本文中的資訊是根據特定實驗室環境內的裝置所建立。文中使用到的所有裝置皆從已清除(預設)的組態來啟動。如果您的網路運作中,請確保您瞭解任何指令可能造成的影響。
症狀
系統會生成以下警報:
20 May 2025 07:37:04 +0700 Connection to URL Retrospective registration service failed. Certificate verification failed. Contact Cisco TAC for assistance.
這些警報將傳送到已配置的電子郵件地址。如果電子郵件地址尚未與警報關聯,則可通過導航到系統管理 >> 警報並按一下檢視頂級警報或運行displayalerts CLI命令來檢查這些地址。
在ecs日誌中可找到以下錯誤:
esa01.example.com> grep "Warning|Critical" ecs
Fri May 16 18:57:05 2025 Warning: ECS: Cloud query failed. 'Empty polling URI.' 7-xyxxyzxyxxyz (or b'xyxxyzxyxxyzxyxxyzxyxx==' in base64 format) having URLs. Contact Cisco TAC for assistance.
Fri May 16 18:57:31 2025 Critical: ECS: Failed to regenerate token. Status Code: 403. Invalid Certificate.
因應措施
要解決此問題,請建立到裝置的SSH連線並運行ecupdate force:
esa01.example.com> ecupdate force
Requesting forced update of Enrollment Client.
要驗證註冊客戶端更新是否成功,請監控updater_logs和ecs日誌:
esa01.example.com> tail updater_logs
Tue May 20 11:26:19 2025 Info: Received remote command to signal a manual update
Tue May 20 11:26:51 2025 Info: Acquired server manifest, starting update 9030
Tue May 20 11:26:51 2025 Info: Server manifest specified an update for case
Tue May 20 11:26:52 2025 Info: Server manifest specified an update for enrollment_client
Tue May 20 11:26:52 2025 Info: enrollment_client was signalled to start a new update
Tue May 20 11:26:52 2025 Info: enrollment_client processing files from the server manifest
Tue May 20 11:26:52 2025 Info: enrollment_client started downloading files
Tue May 20 11:26:52 2025 Info: enrollment_client waiting on download lock
Tue May 20 11:26:52 2025 Info: enrollment_client acquired download lock
Tue May 20 11:26:52 2025 Info: enrollment_client beginning download of remote file "http://updates.ironport.com/enrollment_client/3.0/enrollment_client/default/109101"
Tue May 20 11:26:52 2025 Info: enrollment_client released download lock
Tue May 20 11:26:52 2025 Info: enrollment_client successfully downloaded file "enrollment_client/3.0/enrollment_client/default/109101"
Tue May 20 11:26:52 2025 Info: enrollment_client started applying files
Tue May 20 11:26:52 2025 Info: enrollment_client applying file "enrollment_client"
Tue May 20 11:26:52 2025 Info: enrollment_client installing new libexec
Tue May 20 11:26:52 2025 Info: enrollment_client restarting
Tue May 20 11:26:55 2025 Info: enrollment_client verifying applied files
Tue May 20 11:26:55 2025 Info: enrollment_client updating the client manifest
Tue May 20 11:26:55 2025 Info: enrollment_client update completed
Tue May 20 11:26:55 2025 Info: enrollment_client waiting for new updates
esa01.example.com> tail ecs
Tue May 20 09:05:21 2025 Info: ECS: Device registration successful.