<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi againAfter some digging I in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614463#M920345</link>
    <description>&lt;P&gt;Hi again&lt;/P&gt;&lt;P&gt;After some digging I've found a work around for this. In the CSM FAQ and Troubleshooting Guide &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/3-3/troubleshooting/guide/csmts_wrapper/dpts.html#pgfId-1046597"&gt;http://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/3-3/troubleshooting/guide/csmts_wrapper/dpts.html#pgfId-1046597&lt;/A&gt;&amp;nbsp;I found a section about "Changing how security Manager responds to Device Messages". When I followed this and added .*Interface is in use by failover.*$\ to the DCS.properties file on the CSM server my deployments no longer fails with the failover error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nice&lt;/P&gt;</description>
    <pubDate>Thu, 26 Mar 2015 10:48:23 GMT</pubDate>
    <dc:creator>hoffa2000</dc:creator>
    <dc:date>2015-03-26T10:48:23Z</dc:date>
    <item>
      <title>Cisco Security Manager: Failover interface error at deployment</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614462#M920344</link>
      <description>&lt;P&gt;Hi folks&lt;/P&gt;&lt;P&gt;I have an ASA 5505 running 9.2(3) managed through my CSM 4.8 server. Everything has been going fine until I added failover, after that every deployment fails at the point below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Line# 30. (SUCCESS) Sent (Fri Mar 20 12:10:12 EET 2015): interface Ethernet0/7&lt;BR /&gt;&amp;nbsp;Received (Fri Mar 20 12:10:13 EET 2015):&amp;nbsp;&lt;BR /&gt;Line# 31. (ERROR) Sent (Fri Mar 20 12:10:12 EET 2015): &amp;nbsp;switchport access vlan 15&lt;BR /&gt;&amp;nbsp;Received (Fri Mar 20 12:10:13 EET 2015): ERROR: Interface is in use by failover. Remove failover configuration first&lt;BR /&gt;! COMMENT: Device reported error here and stopped accepting further commands&lt;BR /&gt;! COMMENT: BULK END&lt;BR /&gt;! COMMENT: Trying URL: &lt;A href="https://192.168.42.1/admin/config" target="_blank"&gt;https://192.168.42.1/admin/config&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems CSM is walking through all interfaces during deployment and when it reaches the failover interface it cannot proceed since that interface is "special" compared to the others. My first question if of course if I've missed something that caused this, failover is operational? But a larger question would be, why do CSM have to walk through all the interfaces in the first place and if this "feature" can be disabled?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update&lt;/P&gt;&lt;P&gt;It seems if I check the "Allow download on Error" option&amp;nbsp;in Administration - Deployment at least CSM deploys the changes but there is still a nasty error being generated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Fredrik&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:25:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614462#M920344</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2020-02-21T13:25:51Z</dc:date>
    </item>
    <item>
      <title>Hi againAfter some digging I</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614463#M920345</link>
      <description>&lt;P&gt;Hi again&lt;/P&gt;&lt;P&gt;After some digging I've found a work around for this. In the CSM FAQ and Troubleshooting Guide &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/3-3/troubleshooting/guide/csmts_wrapper/dpts.html#pgfId-1046597"&gt;http://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/3-3/troubleshooting/guide/csmts_wrapper/dpts.html#pgfId-1046597&lt;/A&gt;&amp;nbsp;I found a section about "Changing how security Manager responds to Device Messages". When I followed this and added .*Interface is in use by failover.*$\ to the DCS.properties file on the CSM server my deployments no longer fails with the failover error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nice&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 10:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614463#M920345</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2015-03-26T10:48:23Z</dc:date>
    </item>
    <item>
      <title>Thank you, Fredrik!I can</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614464#M920346</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Thank you, &lt;/SPAN&gt;Fredrik!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;I can report that the problem occurs in both 4.7 and 4.8, and that the workaround you posted &lt;STRONG&gt;does work&lt;/STRONG&gt;/allows the policy to be deployed.&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;I opened a TAC case for this, and TAC reported this is a "regression defect" and there is a new bug for it, &lt;SPAN style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;CSCut07447 (&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://tools.cisco.com/bugsearch/bug/CSCut07447/?referring_site=bugquickviewclick"&gt;https://tools.cisco.com/bugsearch/bug/CSCut07447/?referring_site=bugquickviewclick)&lt;/A&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;.&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;I referenced&amp;nbsp;your post when I opened the case, and TAC reported it should work (and to let them know if it did).&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;It makes sense that the fix is in a document for CSM 3.3:&amp;nbsp; old bug, old fix &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;One note (that is explained in the CSM FAQ document above):&amp;nbsp; when you add the line to the "PIX Warning expressions" section of DCS.properties file, add it &lt;U&gt;above&lt;/U&gt; the last line of that section - the whole list of error messages has to end with "$", not "$\"&amp;nbsp; .&amp;nbsp; If the list of messages in the section doesn't end with "$", it does not work (see Step 5, "&lt;STRONG&gt;except for the last expression&lt;/STRONG&gt;, you must delimit all expressions with "$\""). I initially added the new message as the last line, and the deploy still failed.&amp;nbsp; Moving it up a line did the trick.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;Saved me a lot of grief, thank you!&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2015 11:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614464#M920346</guid>
      <dc:creator>Karen Kelch</dc:creator>
      <dc:date>2015-03-27T11:58:34Z</dc:date>
    </item>
    <item>
      <title>Excellent. Old bug indeed. </title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614465#M920347</link>
      <description>&lt;P&gt;Excellent. Old bug indeed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2015 13:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-failover-interface-error-at-deployment/m-p/2614465#M920347</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2015-03-27T13:13:04Z</dc:date>
    </item>
  </channel>
</rss>

