09-13-2017 10:42 AM - edited 03-08-2019 07:41 PM
Hi,
I'm using SMA appliance to configure 2 WSA servers.
When i make a modification on ACL and publish to WSA i receive 2 mails from the 2 WSA :
The Critical message is: An application fault occurred: ('acl_gen/gen_util.py instantiateMembership|321', "", 'can only concatenate list (not "tuple") to list', '[egg/configdefragd.py handle_configuration_update|3179] [egg/configdefragd.py update_acl_rules|506] [egg/configdefragd.py _generate_acl_rules|457] [acl_gen/AclGenerator.py run|92] [acl_gen/https_generator.py ruleGenerator|602] [acl_gen/base_generator.py ruleGenerator|196] [acl_gen/base_generator.py genPolicyRules|160] [acl_gen/https_generator.py generate|559] [acl_gen/gen_util.py instantiateMembership|321]') Product: Cisco S390 Web Security Appliance Model: S390 Version: 10.1.1-235
The configuration on the 2 WSA is not applied until i reboot the 2 servers ....
Can you help me ?
09-18-2017 05:53 AM
Hi,
did you contact Cisco TAC?
09-18-2017 06:04 AM
Yes forsure, ticket is open and i wait for a solution ...
Regards
09-18-2017 06:15 AM
09-19-2017 09:06 AM
Just finish the webex with the TAC, it works again.
There is a Bug when using user agent in ACL or profil list or decryption policy.
To solve it, the tac had backup the conf on a WSA and import it to SMA, reboot the WSA and publish the conf from the WSA.
It works until we use user agent. In my case user agent is not important so my problem is solved ;)
Thanks Freddy and Roberto ;)
09-19-2017 11:35 PM
That's great!
We got this message. Did you got the same message?
An application fault occurred: ('acl_gen/gen_util.py instantiateMembership|321', "<type 'exceptions.TypeError'>", 'can only concatenate list (not "tuple") to list', '[egg/configdefragd.py handle_configuration_update|3407] [egg/configdefragd.py update_acl_rules|526] [egg/configdefragd.py _generate_acl_rules|475] [acl_gen/AclGenerator.py run|93] [acl_gen/base_generator.py ruleGenerator|196] [acl_gen/base_generator.py genPolicyRules|160] [acl_gen/base_generator.py generate|81] [acl_gen/gen_util.py instantiateMembership|321]')
We have opened a TAC case and the engineer told us that it's this bug CSCvd70510
As a workaround you can create a new identity and: 1. Add any custom user agent value2. Exclude the predefined user agent setting
It seems that we got hit by the same bug, right?
09-19-2017 11:44 PM
Exactly the same bug !
same message in displayalert
we have test the workaround (CSCvd70510) without success
but backup config on WSA and restore config on SMA work great
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide