cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1677
Views
0
Helpful
3
Replies

Unable to create Intrusion Rules in FMC

gsturcotte
Level 1
Level 1

Hi,

Does anyone have this problem: I am unable to create a new Intrusion rules (Objects->Intrusion Rules->Create Rules) if my user role have the system permission "Set this role to escalate to:" enabled. Each time, I submit a new rule with the button "save as new", the system say:

"An unauthorized action has been detected. This activity has been logged.
This may be a security issue."

and log me out.

My FMC version is 6.2.3.4

 

 

3 Replies 3

Ajay Saini
Level 7
Level 7

Hello,

 

The condition does not match but there is a bug that talks about the logout scenario:

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf01839

 

What is the user role privilege level, are you able to add other objects using the same user like network etc.

 

Regards,

AJ

We use custom user role (the default user role cannot set the "role to escaladate to"). A copy of any default user role with the "role to escaladate to" enabled seem to generate the problem. Any other object can be created without any logout problem.

Ben Guldan
Level 4
Level 4

I had a similar issue, can't really make any significant changes other than deploying policies. Not exactly matching the bug, as I have timeouts applied to CLI and web interface. I'm running FMCv 6.1.0.6.

 

I was able to resolve by switching from Chrome to Firefox.  Did not work with Chrome 70.0.3538.77, did work with Firefox 63.0.1.

Review Cisco Networking for a $25 gift card