cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2140
Views
0
Helpful
6
Replies

Troubleshooting to publish SMA to WSA

cchrisment
Level 1
Level 1

Hi,

 

I'm using SMA appliance to configure 2 WSA servers.

When i make a modification on ACL and publish to WSA i receive 2 mails from the 2 WSA :

The Critical message is:

An application fault occurred: ('acl_gen/gen_util.py instantiateMembership|321', "", 'can only concatenate list (not "tuple") to list', '[egg/configdefragd.py handle_configuration_update|3179] [egg/configdefragd.py update_acl_rules|506] [egg/configdefragd.py _generate_acl_rules|457] [acl_gen/AclGenerator.py run|92] [acl_gen/https_generator.py ruleGenerator|602] [acl_gen/base_generator.py ruleGenerator|196] [acl_gen/base_generator.py genPolicyRules|160] [acl_gen/https_generator.py generate|559] [acl_gen/gen_util.py instantiateMembership|321]')

Product: Cisco S390 Web Security Appliance
Model: S390
Version: 10.1.1-235

The configuration on the 2 WSA is not applied until i reboot the 2 servers ....

Can you help me ?

6 Replies 6

smailmilak
Level 4
Level 4

Hi,

 

did you contact Cisco TAC?

Yes forsure, ticket is open and i wait for a solution ...

 

Regards

Great. I just got a notice that we have this issue, too.

Any failures for now is it only informational?


Just finish the webex with the TAC, it works again.

There is a Bug when using user agent in ACL or profil list or decryption policy.

To solve it, the tac had backup the conf on a WSA and import it to SMA, reboot the WSA and publish the conf from the WSA.

It works until we use user agent. In my case user agent is not important so my problem is solved ;)

Thanks Freddy and Roberto ;)

That's great!

 

We got this message. Did you got the same message?

An application fault occurred: ('acl_gen/gen_util.py instantiateMembership|321', "<type 'exceptions.TypeError'>", 'can only concatenate list (not "tuple") to list', '[egg/configdefragd.py handle_configuration_update|3407] [egg/configdefragd.py update_acl_rules|526] [egg/configdefragd.py _generate_acl_rules|475] [acl_gen/AclGenerator.py run|93] [acl_gen/base_generator.py ruleGenerator|196] [acl_gen/base_generator.py genPolicyRules|160] [acl_gen/base_generator.py generate|81] [acl_gen/gen_util.py instantiateMembership|321]')

 

We have opened a TAC case and the engineer told us that it's this bug CSCvd70510

As a workaround you can create a new identity and: 1.       Add any custom user agent value2.       Exclude the predefined user agent setting

 

It seems that we got hit by the same bug, right?

Exactly the same bug !

same message in displayalert

we have test the workaround (CSCvd70510) without success

but backup config on WSA and restore config on SMA work great