Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dbran_2903
Explorer

Security Gateway Member loses Access Control policy after an installation was submitted

Basically the client has a Security Group that works like VSX, each Virtual System running on the VSX has its own Policy Layer, each Security Group has 4 Security Gateways Appliances running, 2 on chassis_1 and another 2 on chassis_2, the issue occurs as follows: sporadically, and it has been repeated on 3 occasions. The issue is that after having sent the Policy Installation for a specific Virtual System, it is installed correctly in some of the members, however in other members it is not installed and it is observed by running the command vsx stat -v that the Virtual System in question shows as <No policy> in the Access Control column, cases have been opened to TAC but they have only indicated that "it appears to be a memory leak" they have also recommended being on the latest recommended hotfix, which has been done and still So the same issues continue to arise.

Any suggestions or recommendations?

The Security Group is in version R81.20 and has the JHF 89, there are two sites (chassis1 and chassis2) each chassis have two gateway appliances working. The Security Group is running as VSX mode and there are a lot of Virtual Systems running in it.

Thank you so much

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

What does an fw stat show in the relevant VS context?

0 Kudos
the_rock
Legend
Legend

I believe from your screenshot if Im "reading" it correctly, shows that VS has no polucy?

Andy

0 Kudos
AkosBakos
Leader Leader
Leader

Interesting, maybe initial polcy could be OK, but no policy... 

A devil made an fw unloadlocal in the background, just kidding 🙂

----------------
\m/_(>_<)_\m/
Chris_Atkinson
Employee Employee
Employee

Just a quick PSA please see the 'Important Notes' for Jumbo T89 as relevant to Maestro so you're across some of the other known issues should they arise.

Side note - What gateway hardware is used and how much RAM is installed?

CCSM R77/R80/ELITE
0 Kudos