<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC Deleted Rule by itself !? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-deleted-rule-by-itself/m-p/4400124#M1080635</link>
    <description>&lt;P&gt;I have encountered a similar issue with Firepower 6.7.0 managed with FDM. In my base, site-site VPN configs were lost and had to be recreated manually. TAC was likewise unable to replicate - even though they observed it happening in real time on the production Firepower 2140 HA pair.&lt;/P&gt;</description>
    <pubDate>Mon, 10 May 2021 09:02:16 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-05-10T09:02:16Z</dc:date>
    <item>
      <title>FMC Deleted Rule by itself !?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-deleted-rule-by-itself/m-p/4400116#M1080632</link>
      <description>&lt;P&gt;We recently had a major issue where the FMC deleted a rule apparently by itself !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FMC1600 physical device running 6.6.1&lt;/P&gt;&lt;P&gt;Senario, I deleted some out of date office IP's &amp;amp; associated rules. Applied policy to FTD's &amp;amp; a major incident became evident. After some diagnosis it transpired that our primary customer web access rules was missing !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the policy diff compare, shows all the actions I took, then at the bottom (last item) it shows the web access rules as deleted from old policy &amp;amp; added in new saved policy. But when looking at the live installed policy the rule was missing !?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recreated the rule manually (no roll back function in FMC) which restored the service.&amp;nbsp; Cisco TAC agree the diff compare is odd, but can not provide an explanation for why a rule that was NOT modified appeared in the diff compare nor why it was missing from the policy where it clearly indicates it should exist ???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have tried various tests with TAC, but troubleshoot files don't indicate any issues &amp;amp; TAC have NOT been able to replicate it in a lab, nor restore my backups, as they have discovered that physical FMC backup will NOT restore to Virtual LAB vFMC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else experienced any weird rule issues ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Points to note,&lt;/P&gt;&lt;P&gt;FMC diff compare does NOT record actual rule numbers, it numbers the changes as Rule1-RuleX as they are made, no relation to the rulebase rule number, only the Rulename is consistent with the rulebase.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The audit log does NOT record changes to policy, only the policy save diff compare shows changes made between policy opened &amp;amp; new policy saved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 08:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-deleted-rule-by-itself/m-p/4400116#M1080632</guid>
      <dc:creator>ida71</dc:creator>
      <dc:date>2021-05-10T08:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Deleted Rule by itself !?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-deleted-rule-by-itself/m-p/4400124#M1080635</link>
      <description>&lt;P&gt;I have encountered a similar issue with Firepower 6.7.0 managed with FDM. In my base, site-site VPN configs were lost and had to be recreated manually. TAC was likewise unable to replicate - even though they observed it happening in real time on the production Firepower 2140 HA pair.&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 09:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-deleted-rule-by-itself/m-p/4400124#M1080635</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-10T09:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Deleted Rule by itself !?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-deleted-rule-by-itself/m-p/4400128#M1080637</link>
      <description>&lt;P&gt;Thanks Marvin, at least I'm not going crazy. I have spent a while looking at previous diff compares &amp;amp; I don't see this replicated previously. As an indication there have been over 5000 successful policy changes in the last 14 months.&lt;/P&gt;&lt;P&gt;As a precaution we are now viewing policy diff compares before applying policy &amp;amp; only applying policy out of core hours, which is a pain.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 09:10:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-deleted-rule-by-itself/m-p/4400128#M1080637</guid>
      <dc:creator>ida71</dc:creator>
      <dc:date>2021-05-10T09:10:48Z</dc:date>
    </item>
  </channel>
</rss>

