<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Signature Update - CSM v3.3 SP1 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491755#M923260</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Scott....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I am using shared policies and also v7 (since when the problem has occured).&amp;nbsp; I've added a DNS shared policy and will check with the next signature application (already did 502 earlier today).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Liam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Jul 2010 12:27:39 GMT</pubDate>
    <dc:creator>liamwalk1971</dc:creator>
    <dc:date>2010-07-22T12:27:39Z</dc:date>
    <item>
      <title>IPS Signature Update - CSM v3.3 SP1</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491753#M923258</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting the following error message when deploying IPS signature updates to some of my sensors via the CSM deployment tool:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Failed to generate edit config delta&amp;nbsp; for host component. Detail: Error while processing the host component with DNS,access-list or http-proxy"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The signature update actually deploys, but I am wondering what is causing this message.&amp;nbsp; I get this with some 4240, 4255 and IDSM-II blades, but not with others and I can't see any config variances.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas what is causing this message?&amp;nbsp; The access ACLs are the same for each sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491753#M923258</guid>
      <dc:creator>liamwalk1971</dc:creator>
      <dc:date>2020-02-21T12:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Signature Update - CSM v3.3 SP1</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491754#M923259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Liam;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Are you making use of shared policy on these devices?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; If these sensors are running IPS release 7.0, have you ensured that at least one DNS server is configured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 11:50:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491754#M923259</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-07-22T11:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Signature Update - CSM v3.3 SP1</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491755#M923260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Scott....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I am using shared policies and also v7 (since when the problem has occured).&amp;nbsp; I've added a DNS shared policy and will check with the next signature application (already did 502 earlier today).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Liam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 12:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491755#M923260</guid>
      <dc:creator>liamwalk1971</dc:creator>
      <dc:date>2010-07-22T12:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Signature Update - CSM v3.3 SP1</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491756#M923261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Liam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you mentioned you are using a shared policy, and the access ACLs for all sensors are the same, I assume that you may be using an "Allowed Hosts" shared policy. &lt;/P&gt;&lt;P&gt;In that case, how did you create that policy ? &lt;/P&gt;&lt;P&gt;Did you create the policy from the policy view page, or did you right click on the "Allowed Hosts" setting of a device in device view and select "share policy" ?&lt;/P&gt;&lt;P&gt;If you did the first, you may be running into a known issue. You can read more about this on the bug toolkit:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtg02063"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtg02063&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the workaround that should work for you in case you are indeed running into this issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Rediscover or newly add any one IPS device running 7.x version&lt;/P&gt;&lt;P&gt;2. Create entries for "Allowed Hosts" according to requirements.&lt;/P&gt;&lt;P&gt;3. Right click on "Allowed Hosts", select "Share Policy..." and specify a name for shared policy.&lt;/P&gt;&lt;P&gt;4. Assign this "Allowed Hosts" shared policy to one or more devices.&lt;/P&gt;&lt;P&gt;5. Deployment should now be successful for "Allowed Hosts".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 13:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491756#M923261</guid>
      <dc:creator>Stijn Vanveerdeghem</dc:creator>
      <dc:date>2010-07-22T13:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Signature Update - CSM v3.3 SP1</title>
      <link>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491757#M923262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your assistance Scott.&amp;nbsp; The application of S503 worked wi&lt;SPAN style="background-color: #f8fafd;"&gt;thout error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Liam&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 08:55:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-signature-update-csm-v3-3-sp1/m-p/1491757#M923262</guid>
      <dc:creator>liamwalk1971</dc:creator>
      <dc:date>2010-07-29T08:55:28Z</dc:date>
    </item>
  </channel>
</rss>

