<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem deploying flex-config for policy-based routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-deploying-flex-config-for-policy-based-routing/m-p/4761281#M1097153</link>
    <description>&lt;P&gt;We have an HA pair of 2140 FTDs running 7.0.4 managed by an FMCv also running 7.0.4. We've had PBR configured since April of last year, which is allowing us to migrate to a new edge network with new Internet routers and set of ISPs running BGP. As we get approval to move other subnets and hosts over to the new edge, which is usually a few a month, we do so with no problems. We attempted to add some new devices to the PBR configuration yesterday, but the deployment failed. We removed the configuration, deployment still failed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new TAC case, but I don't have confidence with the state of the firewall. PBR was configured with flex-config using Type: Append and Deployment: Everytime. The ONLY way we could deploy after yesterday's failure was to change Type: Prepend and Deployment: Once. The TAC engineer claims PBR will remain in the configuration after subsequent deployments, but that's not been my experience.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the error information from a failed deployment when I attempt to change back to Type: Append and Deployment: Everytime.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Lina messages&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;ErrorCode: CFG-IN-PROGRESS Severity: error Description: com.cisco.ngfw.messages.DescriptionType@3b23f0d3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;FMC &amp;gt;&amp;gt; clear configuration session OBJECT&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;U&gt;Other logs&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Lina config ROLLBACK failure log&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Lina configuration application failure. Error in lina apply phase due to Config System Error response from LINA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Lina Files Rollback successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We'll have a major outage if PBR drops out of the configuration, so I refused to attempt a second deployment with the TAC engineer today to test my expectation. My questions are the following: 1) Will the PBR configuration drop with Deployment: Once set? 2) Based on the error message, is there potentially something else I can try? Maybe a reboot?&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 19:37:37 GMT</pubDate>
    <dc:creator>ABaker94985</dc:creator>
    <dc:date>2023-01-24T19:37:37Z</dc:date>
    <item>
      <title>Problem deploying flex-config for policy-based routing</title>
      <link>https://community.cisco.com/t5/network-security/problem-deploying-flex-config-for-policy-based-routing/m-p/4761281#M1097153</link>
      <description>&lt;P&gt;We have an HA pair of 2140 FTDs running 7.0.4 managed by an FMCv also running 7.0.4. We've had PBR configured since April of last year, which is allowing us to migrate to a new edge network with new Internet routers and set of ISPs running BGP. As we get approval to move other subnets and hosts over to the new edge, which is usually a few a month, we do so with no problems. We attempted to add some new devices to the PBR configuration yesterday, but the deployment failed. We removed the configuration, deployment still failed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new TAC case, but I don't have confidence with the state of the firewall. PBR was configured with flex-config using Type: Append and Deployment: Everytime. The ONLY way we could deploy after yesterday's failure was to change Type: Prepend and Deployment: Once. The TAC engineer claims PBR will remain in the configuration after subsequent deployments, but that's not been my experience.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the error information from a failed deployment when I attempt to change back to Type: Append and Deployment: Everytime.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Lina messages&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;ErrorCode: CFG-IN-PROGRESS Severity: error Description: com.cisco.ngfw.messages.DescriptionType@3b23f0d3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;FMC &amp;gt;&amp;gt; clear configuration session OBJECT&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;U&gt;Other logs&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Lina config ROLLBACK failure log&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Lina configuration application failure. Error in lina apply phase due to Config System Error response from LINA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Lina Files Rollback successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We'll have a major outage if PBR drops out of the configuration, so I refused to attempt a second deployment with the TAC engineer today to test my expectation. My questions are the following: 1) Will the PBR configuration drop with Deployment: Once set? 2) Based on the error message, is there potentially something else I can try? Maybe a reboot?&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 19:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-deploying-flex-config-for-policy-based-routing/m-p/4761281#M1097153</guid>
      <dc:creator>ABaker94985</dc:creator>
      <dc:date>2023-01-24T19:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Problem deploying flex-config for policy-based routing</title>
      <link>https://community.cisco.com/t5/network-security/problem-deploying-flex-config-for-policy-based-routing/m-p/4761320#M1097155</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/217588-configure-pbr-with-ip-slas-for-dual-isp.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/217588-configure-pbr-with-ip-slas-for-dual-isp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 20:31:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-deploying-flex-config-for-policy-based-routing/m-p/4761320#M1097155</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-24T20:31:41Z</dc:date>
    </item>
  </channel>
</rss>

