<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bug in FWSM-module software v4.x?! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/bug-in-fwsm-module-software-v4-x/m-p/1950777#M401031</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was always under the impression the nameif characters can be as long as 48. I guess I learnt something new today &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 19 Aug 2012 17:26:38 GMT</pubDate>
    <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
    <dc:date>2012-08-19T17:26:38Z</dc:date>
    <item>
      <title>Bug in FWSM-module software v4.x?!</title>
      <link>https://community.cisco.com/t5/network-security/bug-in-fwsm-module-software-v4-x/m-p/1950776#M401030</link>
      <description>&lt;P&gt;Hi, ive seen some strange behavior in multiple context configuration in FWSM module in a 6509-E chassis when using Security Manager to deploy configs.&lt;/P&gt;&lt;P&gt;Software version in FWSM is 4.1(7), and the 6509-E has IOS 12.2(33)SXJ2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When deploying a config (changed inspect protocols) from CSM (tested both version 3.3.1 and 4.2) to a context it will fail with authentication error&lt;/P&gt;&lt;P&gt;and the aaa/tacacs+ config is erased/modifed !!(eg. aaa server....)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Buggy" config as follows (relevant parts...):&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Vlan1043&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;description Net_Aggr_Link_Elev only for Management&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nameif Rve_Link_Net_Aggr_Elev&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ip address 10.100.255.193 255.255.255.240&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;management-only&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ protocol tacacs+&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ (Rve_Link_Net_Aggr_Elev) host 172.23.16.24&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;timeout 5&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;key xxxxxxxx&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ (Rve_Link_Net_Aggr_Elev) host 172.23.16.16&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;timeout 5&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;key xxxxxxxx&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No commands in the deploy (seen in CSM) that affects the aaa config is visible, only the poilcy-map/inspect commands as expected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After deployment from the CSM, the aaa config is changed(!) and the key is missing from running config!! (see below)&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Vlan1043&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;description Net_Aggr_Link_Elev only for Management&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nameif Rve_Link_Net_Aggr_Elev&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ip address 10.100.255.193 255.255.255.240&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;management-only&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ protocol tacacs+&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ (Rve_Link_Net_Aggr_Elev) host 172.23.16.24&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;timeout 5&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ (Rve_Link_Net_Aggr_Elev) host 172.23.16.16&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ive checked the syntax for the &lt;STRONG&gt;interface/nameif&lt;/STRONG&gt; command to see if the name was too long but the max length is 48 char so this seem to be OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the syntax for the aaa-server command does not describe any limitations to the inteface name.(suspicious...hm!)&lt;/P&gt;&lt;P&gt;So i decided to change the nameif for the above interface to a shorter name (from 22 char to 4 char) as ive seen some similar problem in other areas with too long character strings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i changed the interface nameif string in context running config, rediscovered (live device) the context back into CSM and then made some changes for deployment in the CSM.&lt;/P&gt;&lt;P&gt;And this time it worked, this was clearly the problem. The interface namif string must be short, probable less than 16 characters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Working config as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Vlan1043&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;description Net_Aggr_Link_Elev only for Management&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nameif Mgmt&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ip address 10.100.255.193 255.255.255.240&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;management-only&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ protocol tacacs+&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ (Mgmt) host 172.23.16.24&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;timeout 5&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;key xxxxxxxx&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa-server XYZ (Mgmt) host 172.23.16.16&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;timeout 5&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;key xxxxxxxx&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone who has seen this behavior??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:40:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bug-in-fwsm-module-software-v4-x/m-p/1950776#M401030</guid>
      <dc:creator>Ulrik Rosen</dc:creator>
      <dc:date>2019-03-11T23:40:09Z</dc:date>
    </item>
    <item>
      <title>Bug in FWSM-module software v4.x?!</title>
      <link>https://community.cisco.com/t5/network-security/bug-in-fwsm-module-software-v4-x/m-p/1950777#M401031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was always under the impression the nameif characters can be as long as 48. I guess I learnt something new today &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Aug 2012 17:26:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bug-in-fwsm-module-software-v4-x/m-p/1950777#M401031</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-19T17:26:38Z</dc:date>
    </item>
  </channel>
</rss>

