cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7742
Views
5
Helpful
13
Replies

Intrusion policy, Policy out-of-date on device

dm
Level 1
Level 1

Hello!

 

I use ASDM to manage Firepower on ASA 5506-X.

I just found that  in  Configuration > ASA FirePOWER Configuration > Policies > Intrusion Policy > Intrusion Policy

my policy is always shown as Policy out-of-date on device.

I tried to change it, to change access control policy in which it is in use, did deploy- there is no changes,

it is always Policy out-of-date on device.

 

Could you tell me how to solve this?

 

Currently running software version: 6.2.3.10

 

Thank you!

13 Replies 13

dm
Level 1
Level 1
btw, upgraded to 11, no changes.

johnlloyd_13
Level 9
Level 9

hi,

did you click 'Click Store ASA FirePOWER Changes' at the bottom?

I have this problem on 3 devices, nothing helps...

gregghudson
Level 1
Level 1

I have this exact same problem. Nothing clears the error. I go into the IPS and click "Commit Changes", go to Access Control Policy (and it says 'Up-to-date') and click "Store ASA FirePOWER Changes",  then "Save Running Configuration to Flash" and even after 'deploy' it still show's "Out-of-date". And this is on 5 different firewalls!

I'm seeing this exact same problem as well.

Has anyone found a solution to this issue?  

It could be caused by a corrupted entry with the database.

I recommend opening a TAC case to get into the level of troubleshooting that necessary to confirm and remedy the issue.

I don't think there is any corruption here but software bug :-)

Bugs can cause database corruption. :)

Cisco TAC says "known bug".

Did they supply a bug number?

Review Cisco Networking products for a $25 gift card