Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Parabol
Contributor

Threat Prevention Policy fails to install to one security gateway only (Failed to handle indicators)

Hi all, we have an issue when installing the threat prevention policy to one particular gateway cluster (It's a VSX HA cluster). It is successful on the Standby member, and fails on the Active.

The error is: Failed to handle indicators, < csc6921a-c75f-4ef8-12f4-39aa15718ccf>). (screenshot attached)

It is worth mentioning that we only just upgraded our management server to R82 and so I am sure this has influenced this, gateways remain on R81.20 for now. However, because threat prevention policy installs successfully to every other gateway cluster we have, it surely is something specific to this gateway.

Do you guys have any thoughts on how to troubleshoot? I did try removing the indicators in the Threat Prevention policy and then installing again, but the error remains. It's strange how it is successful to the Standby cluster member, but not the Active.

Thanks

 

EDIT: To follow up, the string in the error seems to match to this binary file:

 

[Expert@:0]# grep -ri "csc6921a-c75f-4ef8-12f4-39aa15718ccf" $FWDIR
Binary file /opt/CPsuite-R81.20/fw1/lib/libamw_fetch.so matches

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

One TAC case suggests deleting and re-adding the relevant feed on the relevant gateway (or VS in your case).
If that doesn't work, I suggest engaging with TAC.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 07 Oct 2025 @ 09:30 AM (CEST)

    CheckMates Live Denmark!
    CheckMates Events