- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Has anyone run into (and hopefully resolved) '...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Has anyone run into (and hopefully resolved) 'convert_asm_web_security: failed to create 'http_enforce_sql_injection' from 'HTTP_security_server'?
Has anyone run into (and hopefully resolved) 'convert_asm_web_security: failed to create 'http_enforce_sql_injection' from 'HTTP_security_server', Failed to convert web security parameters in asm.C, internal error occurred during the verification process, Policy verification failed after R77.30 db export and import into R80.10?
The issue is specific to the IPS SQL Injection protection and policy successfully pushes if this protection is inactivated but we would like to continue to use this protection.
Screenshot of the specific error attached.
Support is assisting and opening a case with R&D but wondering if others have encountered and hopefully even resolved this issue? This appears to be the only post-upgrade issue but it is preventing us from moving to the R80.10 management server.
Any and all assistance is appreciated.
- Tags:
- failed to convert web security parameter in asm.c
- failed to create http_enforce_sql_injection
- sql injection protection errors after r80.10 upgrade
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Long shot, especially if you're already escalated to level 3 - but have you looked at your rulebase order to make sure any rules using legacy application layer servers (like the HTTP security server) come *before* any rules that use the new application control and protocol inspection stuff?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It looks like the error and issue is strictly related to the SQL Injection IPS protection. If I disable this protection, I can successfully push policy, however, we want to be able to utilize the SQL Injection protection.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi guys, a mid-way update on this issue - was an internal error with the policy installation engine. This does not relate to any kind of user misconfiguration. Aaron will be notified once a fix + SK arrive.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good deal. Please let us know when the SK is up. I'd like to check in with my customers on this one. Kind of surprised we didn't trip over this already.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi guys, the decision was that each time such thing happens, you would have to contact Check Point Support. The problem was an internal error with the policy installation engine, and that error does not currently repeat for other customers.
