<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Duplicated objects after push to firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320379#M920177</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Meda,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mentioned that the duplication happens in case You're doin the discovery from the real device. At the time of discovery procedure CSM creates objects in its database with the _x suffix and the same values as in an "old" objects (without _x).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And at the next deploy CSM replaces old objects with a new ones. What I'm doing:&lt;/P&gt;&lt;P&gt;1) copying access-rules policy somewhere&lt;/P&gt;&lt;P&gt;2) discovery from the device device&lt;/P&gt;&lt;P&gt;3) clearing parsed config in Access Rules (deleting rules)&lt;/P&gt;&lt;P&gt;4) pasting rules that were copied earlier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result: the config is synchronized between CSM DB and the FW. No new objects are used.&lt;/P&gt;&lt;P&gt;This is a workaround, not a normal situation (otherwords - bug). Do not understand why it's needed to create new objects instead of using existed ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Just opened a case in Cisco TAC: changed the Global ACL (inheritance) for the FW. After that some of rules were missed in real device but existed in CSM DB. Branch was down for 2 hours.. Be aware and do preview config each time making deploy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My CSM version is 4.4 SP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Oct 2013 14:22:12 GMT</pubDate>
    <dc:creator>4nt0n_Zamaraev</dc:creator>
    <dc:date>2013-10-03T14:22:12Z</dc:date>
    <item>
      <title>Duplicated objects after push to firewall</title>
      <link>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320378#M920176</link>
      <description>&lt;P&gt;Hello, we recently updgrade CSM to 4.3.0 service pack2 and we figure out that objet are duplicated with _xx when push are perform to FW asa version 8.4.How i can resolve the problem in order to avoid this duplicated objets.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:00:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320378#M920176</guid>
      <dc:creator>Yasm</dc:creator>
      <dc:date>2020-02-21T13:00:17Z</dc:date>
    </item>
    <item>
      <title>Duplicated objects after push to firewall</title>
      <link>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320379#M920177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Meda,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mentioned that the duplication happens in case You're doin the discovery from the real device. At the time of discovery procedure CSM creates objects in its database with the _x suffix and the same values as in an "old" objects (without _x).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And at the next deploy CSM replaces old objects with a new ones. What I'm doing:&lt;/P&gt;&lt;P&gt;1) copying access-rules policy somewhere&lt;/P&gt;&lt;P&gt;2) discovery from the device device&lt;/P&gt;&lt;P&gt;3) clearing parsed config in Access Rules (deleting rules)&lt;/P&gt;&lt;P&gt;4) pasting rules that were copied earlier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result: the config is synchronized between CSM DB and the FW. No new objects are used.&lt;/P&gt;&lt;P&gt;This is a workaround, not a normal situation (otherwords - bug). Do not understand why it's needed to create new objects instead of using existed ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Just opened a case in Cisco TAC: changed the Global ACL (inheritance) for the FW. After that some of rules were missed in real device but existed in CSM DB. Branch was down for 2 hours.. Be aware and do preview config each time making deploy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My CSM version is 4.4 SP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 14:22:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320379#M920177</guid>
      <dc:creator>4nt0n_Zamaraev</dc:creator>
      <dc:date>2013-10-03T14:22:12Z</dc:date>
    </item>
    <item>
      <title>Duplicated objects after push to firewall</title>
      <link>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320380#M920178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Anton,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSM is nightmare &lt;SPAN __jive_emoticon_name="devil" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;, i will test your solution and i send you back a mail to give the result so thank you very much for our help &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Meda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 15:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320380#M920178</guid>
      <dc:creator>Yasm</dc:creator>
      <dc:date>2013-10-04T15:17:53Z</dc:date>
    </item>
    <item>
      <title>Duplicated objects after push to firewall</title>
      <link>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320381#M920179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Anton,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Copying access-rules policy from FW or CSM ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Meda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Oct 2013 14:30:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/duplicated-objects-after-push-to-firewall/m-p/2320381#M920179</guid>
      <dc:creator>Yasm</dc:creator>
      <dc:date>2013-10-16T14:30:58Z</dc:date>
    </item>
  </channel>
</rss>

