Table Of Contents
Release Notes for Cisco Security Manager 3.1
What's New in Security Manager 3.1
Security Manager Resolved Problems
Security Manager Known Problems
Catalyst 6500/7600 Configuration
Diagnostics, Monitoring, and Troubleshooting Tools
Site-to-Site/Remote Access/SSL VPN Configuration
IPS and IOS IPS in Security Manager 3.1
IPS and IOS IPS in Security Manager Notes
IPS and IOS IPS in Security Manager Resolved Problems
IPS and IOS IPS in Security Manager Known Problems
New Features in Security Manager 3.1
Obtaining Documentation, Obtaining Support, and Security Guidelines
Release Notes for Cisco Security Manager 3.1
Revised: June 20, 2007, OL-11477-04CDC Date June 1, 2007Contents
Introduction
This document contains release note information for the following:
Note
Before using Cisco Security Manager 3.1, we recommend that you read this entire document. However, it is critical that you read the "Important Notes" section, the "Installation and Upgrade" section, and the Installation Guide for Cisco Security Manager 3.1 before installing or upgrading to Cisco Security Manager 3.1.
•
Cisco Security Manager 3.1
Cisco Security Manager (Security Manager) enables you to manage security policies on Cisco security devices. Security Manager supports integrated provisioning of VPN and firewall services across IOS routers, PIX and ASA security appliances, and Catalyst 6500/7600 services modules (FWSM and VPNSM). Security Manager also supports provisioning of many platform-specific settings, for example, interfaces, routing, identity, QoS, logging, and so on.
Security Manager efficiently manages a wide range of networks, from small networks consisting of a few devices through to large networks with thousands of devices. Scalability is achieved through a rich feature set of shareable objects and policies and device grouping capabilities.
Security Manager supports multiple configuration views optimized around different task flows and use cases.
•
Auto Update Server 3.1
The Auto Update Server (AUS) is a tool for upgrading PIX security appliance software images, ASA software images, PIX Device Manager (PDM) images, Adaptive Security Device Manager (ASDM) images, and PIX security appliance and ASA configuration files. Cisco IOS routers that have dynamic IP addresses communicate with AUS that is running the Cisco Networking Services (CNS) Gateway Protocol to provide their IP addresses.
Security Manager can interoperate with AUS. To manage the devices in Security Manager, you must provide the device identity and the AUS information when you add a device. Security Manager uses the device identity information to retrieve the device IP address from an AUS that can be reached.
•
IPS and IOS IPS in Security Manager 3.1
Security Manager supports fully native IPS provisioning. The predecessor of this native IPS provisioning was the cross-launched component of Security Manager known as IPS Manager.
This release note document includes ID numbers and headlines for each known problem identified in the document and a description of each. This document also includes a list of resolved problems. If you accessed this document from Cisco.com, you can click any ID number, which takes you to the appropriate release note enclosure in the Bug Toolkit. The release note enclosure contains symptoms, conditions, and workaround information.
What's New in Security Manager 3.1
•
Upgrade from Security Manager 3.0 and 3.0.1.
•
Integrated IPS features. While Security Manager 3.0 allowed you to cross-launch the IPS Management Center to access IPS functionality, Security Manager 3.1 provides fully integrated IPS features.
•
Native integrated Catalyst 6500/Cisco 7600 Router and VACL management.
•
Ability to cross-launch IPS Event Viewer 5.2 to monitor IPS sensors.
•
Ability to test the communication between Security Manager and devices that have been or are being added to the inventory.
•
Ability to discover site-to-site and remote access VPNs.
•
Ability to discover IOS router configurations.
•
High availability.
•
Embedded read-only access to SDM, ASDM, IDM, and IEV for monitoring of individual devices.
•
Navigation to access rule policy for ACL-related syslog messages from the real-time syslog viewer of SDM 2.3.4 and ASDM 5.2.2.
•
Navigation to IPS signature policy for IPS events from IEV Realtime Dashboard and Views tab.
•
Enhanced reporting features, including device-centric policy report and inventory report.
•
Device, interface, and VPN up/down status reported in inventory report.
•
Detailed activity report for firewall and IDS devices.
•
Ability to configure SSL VPN on IOS and ASA 7.1/7.2 devices.
•
Cross-launch of RME SWIM for OS management.
•
Ability to use Security Manager user login credentials to connect to devices.
•
Ability to use Telnet as a transport protocol to communicate with IOS and Catalyst 6500/7600 devices.
•
Enhanced device certificate retrieval support including bulk retrieval through CLIs.
•
Support for the following additional features on IOS devices:
–
SSL VPN
–
Additional Easy VPN features
–
Line access
–
SSH configuration
–
Local time
–
Comprehensive AAA support
–
HTTP server
–
PPP
–
DSL/ATM
–
DNS
–
NFP
–
Bridging (wireless)
–
QoS TAC enhancements
–
Authentication proxy enhancements
–
Additional interface settings, such as IP redirect, IP reply, virtual reassembly, and others
–
Additional firewall features, such as support for IM blocking, java list, DOS settings, and voice service inspection
–
Additional IPSec VPN features, such as large-scale DMVPN, AIM III
•
Support for the following additional features on FWSM 3.1:
–
More than one pair of layer 2 interfaces
–
SNMPv2c
–
Skinny video
–
Asymmetric routing
–
FTP authentication challenge
–
Destination NAT for multicast
–
4K global statements
•
Support for the following features on ASA 7.2 devices:
–
Easy VPN HW client parity with PIX 501/506/VPN3002
–
Dual ISP support
–
PPPoE
–
Home/Business VLAN support
–
Enhanced auto-update support
–
Dynamic DNS
–
HA - sub-second failover
–
Virtualization - resource manager
–
Extended usage of DNS domain names
–
Generic input rate limiting
–
MPF-based regular expression classification map
–
N2H2 HTTPS/FTP filtering support
•
Support for the following features on FWSM 3.2:
–
L2 NAT/PAT
–
TACACS+ command enhancements
–
Xlate table bypass
–
H323 GUP support
–
Cut through proxy enhancements
–
RTSP PAT
•
Support for AIM III (IPSec/SSL VPN)
•
Support for IPS 5.1/6.0 and IOS IPS in IOS 12.4(11)Tx
•
Support for the following features on IPS 6.0 devices:
–
Virtual sensors
–
Anomaly detection
–
Passive OS fingerprinting
–
Simplified custom signature creation
–
Signature update wizard, preview and tuning of new signatures
–
IPS signature update license management
–
External product interface (linkage of IPS sensor with CSA MC)
Security Manager 3.1
Important Notes
•
Before you can successfully upgrade to Security Manager 3.1 from a prior version of Security Manager, you must make sure that the Security Manager database does not contain any pending data, meaning data that has not been committed to the database. If the Security Manager database contains pending data, you must commit or discard all uncommitted changes and then back up your database before upgrading. For instructions, see "Upgrading Server Applications" in the Installation Guide for Cisco Security Manager 3.1.
•
When you perform a policy query in Security Manager, interface names are not case sensitive. However, when you perform a policy query in CS-MARS, interface names are case sensitive. For example, outside and Outside are considered exclusive by CS-MARS, while they are equivalent in Security Manager. As a result, a name logged in the syslog event might not match the name in Security Manager. Syslog messages use lowercase for all interface names. To work around this problem, use lowercase for all interface names and in the definition of interface roles in Security Manager.
•
Although FWSM 3.1 can support multiple L2 interface pairs, Security Manager allows you to specify a maximum of two L2 interfaces (a single interface pair) and one associate management IP address. This means only one bridge group with two named interfaces associated is provisioned with a management IP address. A named interface is an interface that is configured with the "nameif" subcommand. If the device configuration contains a maximum of one bridge group and two named interfaces, it is valid for discovery. All other scenarios result in an error message and the commands are ignored during discovery. Furthermore, discovery does not show any bridge-group information in the GUI, but the bridge-group commands are generated during deployment. The bridge group 1 is deployed and used in the transparent rule policies if no bridge group exists in the device configuration. Discovery will stop and display an error if it imports an FWSM 3.1 device configuration that contains more than two named interfaces or more than one bridge group.
•
In IOS 12.3(14)T, many of the predefined inspection protocols were introduced; however, certain commands are not generated if inspection rules configured in Security Manager conflict with port definitions of predefined inspection protocols.
•
For the CS-MARS cross-launch panel to appear on the Cisco Security Manager Suite home page, you need to manually register the CS-MARS appliance on the Common Services application registration page. To do this, perform the following:
1.
From the Cisco Security Manager Suite home page, click the Server Administration link. The Common Services Admin page appears.
2.
Select HomePage Admin > Application Registration. The Application Registrations Status page appears.
3.
Click Register. The Choose Location for Registrations page appears.
4.
Select Register From Templates, then click Next.
5.
Select Monitoring, Analysis and Response System, then click Next.
6.
Enter the server name, server display name, and port and protocol information for the CS-MARS appliance, then click Next.
7.
Verify registration information, then click Finish. The CS-MARS launch point will now appear from the Cisco Security Manager Suite homepage.
Note
If you choose to add the cross-launch to CS-MARS later, simply launch your web browser and enter http://SecManServer:1741, where SecManServer is the name of the computer where Cisco Security Manager Suite is installed. If you are using SSL, the default URL is https://SecManServer:443.
Security Manager Resolved Problems
The following problems were documented in the Security Manager 3.0.1 release notes as known problems and have since been resolved.
Table 1 Resolved Problems
CSCsa81102—Need log input option when creating access rules for IOS devicesDescription: Security Manager does not support the ACE option "log input" when you configure access rules on IOS devices that are managed by Security Manager. As a result, during discovery, Security Manager drops the option.
CSCsb64813—Installation fails on a server on which the PERL5LIB variable is setDescription: The PERL5LIB system environment variable is set on the server. During installation, an error message notes that perl58.dll cannot be found and installation fails.
CSCsb73828—System context should support NTP with interfaceDescription: If you enter an interface name when you configure an NTP server for the system context of an ASA device in multiple context mode, validation for that device fails.
CSCsc13977—Changes in ACS 3.3(x) do not take effect in Security ManagerDescription: Changes that you make under Group Setup and Network Configuration in Cisco Secure Access Control Server (ACS) 3.3(x) are not reflected in Security Manager, even after you restart CiscoWorks Common Services and the Security Manager Client.
CSCsc39178—Changes lost when switching between Device view and undocked Map viewDescription: Changes you made in Device view are lost after you edit the device in the undocked Map view. After you change the window focus from Device view to undocked Map view, you are not prompted to save the changes you made in Device view.
CSCsc42646—Full config needs negative form of some failover commands for PIX 6.xDescription: If you remove a logical interface from Security Manager and you deploy the configuration to the device using AUS, the deployment fails.
CSCsc48462—ACEs with log-input option on IOS devices are removed after redeploymentDescription: Although IOS devices support ACEs that have the option "log-input," Security Manager does not support the feature. On deployment, the option is removed from the ACE.
CSCsc62714—Deployment fails if crypto ACL is not defined on peer deviceDescription: Deployment of a regular IPSec VPN fails on a PIX 6.3 device if one peer in the VPN topology uses an ACL to specify its protected networks and the other peers do not.
CSCsc66744—Client-server communication mechanism encountered "end of file" errorDescription: While working in Security Manager from a client, the following error occurs: "Unknown Error. performBinaryRPC()..." When this occurs, "Premature EOF Error" entries are also logged in the client log file.
CSCsc80085—Router-SNMP community string is shown in clear text for all usersDescription: The community strings defined in SNMP policies on Cisco IOS routers are displayed in clear text, even for users who are assigned roles with view-only permissions.
CSCsd04054—Router-quality of service (QoS) classes cannot be reorderedDescription: You cannot reorder the classes in a QoS policy on a Cisco IOS router.
CSCsd09630—PIX deploy failed after changing IP address and DHCP address poolDescription: Deployment fails for DHCP relay commands and an error message states that the subnet of the DHCP server address pool range is not the same as the subnet of the DHCP server interface.
CSCsd13990—"dhcprelay" and "dhcpd" commands are not generated in the correct orderDescription: If you disable the DHCP server and then enable DHCP relay on the same interface, or if you disable DHCP relay and enable the DHCP server on the same interface, and you deploy both changes at the same time, deployment might fail.
CSCsd21256—A 72xx router cannot be used as remote client in EzVPN topologyDescription: In an EzVPN topology configuration, deployment fails if a 72xx series router is used as a remote client device. The EzVPN client is supported on PIX Firewalls and Cisco 800-3800 Series routers only.
CSCsd21617—Need to modify the webfilter.xml templateDescription: Even if you do not make changes to a configuration and the configuration is previewed or deployed, the filter commands are always cleared and redeployed.
CSCsd28385—Preview configuration error on Catalyst 6500/7600 devicesDescription: Manually adding a Catalyst 6500/7600 device and then immediately running Preview Configuration without defining policies results in an error.
CSCsd28945—Problems duplicating certain object typesDescription: You should not use the Create Duplicate option for the following object types: GTP maps, TCP maps, time ranges, AAA server groups, and PKI enrollments.
CSCsd28972—Routing commands not fully removed from router configurationsDescription: Unassigning a routing policy from a Cisco IOS router does not remove all the CLI commands related to that policy from the device configuration.
CSCsd30760—Optionally remove unreferenced ACLs based on admin settingsDescription: Security Manager does not remove unused access-list commands from a device, for example, if an access-list command has a user-defined name (a name not automatically generated by Security Manager) and is not used by any command, for example, access-group.
CSCsd31803—Unassigning a preshared key policy removes Aggressive Mode optionDescription: If you unassign a preshared key policy in a hub-and-spoke VPN topology, without first saving the policy, the Aggressive Mode option disappears from the UI page.
CSCsd31825—VPN NAT-0 rules not generated when NAT-0 rules are user-definedDescription: If a NAT exemption rule on a PIX 6.3, PIX 7.0 or ASA device already contains user-defined exemption rules, and you select the Do Not Translate VPN Traffic check box in the Translation Options page, Security Manager does not generate additional NAT exemption rules for the VPN traffic.
CSCsd32199—Need to reset FWSM to auto ACL mode before deploying a configurationDescription: Security Manager sets the FWSM device to manual mode when you deploy firewall rule delta information, then resets the device to auto mode when deployment is completed; however, the device remains in manual mode and deployment fails.
CSCsd33142—ACE with "interface" option causes "no access-group..." sent to deviceDescription: After you import or discover a PIX 6.3 device with an ACE using the "interface" keyword and the ACE is bound to the interface by the access-group command, if you deploy to the same device without making any changes, the ACE is removed from the ACL. This occurs if the ACL has other ACEs, or the ACL contains only the ACEs using the "interface" keyword. The access-group command for the ACL is removed from the device when the ACL contains only the ACEs using the "interface" keyword.
CSCsd35411—Wrong message in the audit log after successful discoveryDescription: The audit report might contain a message saying that discovery failed even if discovery is successful. It is safe to ignore this message.
CSCsd37017—Minimized undocked map is not displayed when Map view icon is clickedDescription: If you minimize the undocked Map view, you cannot bring it to the front after clicking the Map View button on the toolbar or selecting the Show in Map View option.
CSCsd37024—Cannot work in undocked Map view because it is on top of modal dialog boxDescription: The undocked Map view is displayed on top of an active dialog box and does not respond to user interaction.
CSCsd37558—Cannot unassign policy if content is being changed on a different deviceDescription: When you change a policy definition, other users are prevented from unassigning that policy from a different device.
CSCsd37616—Two users cannot assign same policy simultaneously on different devicesDescription: If you assign a policy to a device, a different user cannot assign the same policy to a different device.
CSCsd37624—Cannot modify policy content if another user is performing unassignmentDescription: If you unassign a policy from a device, a different user cannot edit the contents of that policy until you submit your changes.
CSCsd38886—Internal error on validation of VPN with Catalyst 6500Description: If your VPN topology contains a Catalyst 6500 device and you have enabled the QoS Preclassify option in the IPSec Proposal, a message indicating that an internal error has occurred appears during validation.
CSCsd39543—Read-only operations require an open activityDescription: If you have no activity opened, then click "Show Source Contents," "Show Original Address Contents," or "Show Translated Address Contents" from the shortcut menu in the Translation Rules table, you are asked to open an activity. These operations are read-only and do not require an opened activity.
CSCsd40127—Incorrect error message for time range objectsDescription: If you enter an invalid time when you define a time range object, the error message that appears does not match the cause of the error.
CSCsd40376—GTP Map for PIX 7.0(4): No provision to configure permit response in GUIDescription: GTP Map in Security Manager does not support the permit response subcommand that was introduced in later versions of PIX OS software. The permit response subcommand from GTP Map CLI in PIX 7.0(4) and greater are dropped during the discovery process and not deployed when the GTP Map is deployed to the device.
CSCsd44545—Add New Version might not close dialog box in Workflow modeDescription: The New Configuration Version dialog box sometimes does not close when you select Configuration > Add > Add New Version from the Tools menu in Workflow mode. This happens if you do not have an open activity. The selection configuration version is added correctly, even though the dialog box does not close.
CSCsd45510—Configuring transparent FW on IOS devices supports only one bridge groupDescription: When you configure transparent firewall on IOS devices, only one bridge group is supported. Bridge group 1 is dedicated to transparent firewall. If you use Bridge Group 1 for something else, and only one interface exists for that group, upon discovery, a validation error results.
CSCsd46022—AAA server loses its defined protocol and becomes uneditableDescription: A AAA server object that is part of a AAA server group loses its defined protocol and becomes uneditable after you change the protocol and fail to specify a key.
CSCsd46041—Validation fails if NAC is configured on an unsupported device typeDescription: After you configure a NAC policy on a router, validation fails. This is because Security Manager allows you to configure a NAC policy on routers that do not support NAC.
CSCsd47010—Read-only users can create policies in Policy viewDescription: Users with read-only (View) permissions can click the Add button in Policy view to create shared policies. In rare cases, this can lead to the deployment of blank policies that overwrite existing device configurations.
CSCsd49009—The "no dhcprelay command" order needs to be done correctly for ASADescription: Deployment fails for DHCP relay commands and an error message states that the device cannot receive DHCP requests and forward them on the same interface.
CSCsd53532—After reinstallation, home page changes to CiscoWorks home pageDescription: If you reinstall Common Services 3.0.3, Security Manager, and Auto Update Server (AUS) on an existing Security Manager server on which Security Manager and AUS are already installed, the home page defaults to the CiscoWorks home page instead of the Security Manager home page.
CSCsd55200—EzVPN Xauth username/password not configured on PIX 6.3 remote clientDescription: The Ea3syVPN tunnel is not created because Xauth authentication fails on the PIX 6.3 remote client. Security Manager does not configure the Xauth username and password that is required for authentication.
CSCsd55435—Objects not displayed in Policy Object Manager after deleting overridesDescription: Deleting a policy object override causes the object on which the override is based to disappear from the Policy Object Manager.
CSCsd56449—"Translating" message appears then deployment of PKI policy failsDescription: Deployment of a PKI policy fails if the URL specified for the CA server contains the CA server's hostname instead of its explicit IP address. Before the deployment failure, a "translating" notification appears to indicate that the device is trying to translate the host name.
CSCsd57440—Security Manager should correctly handle "boot system tftp" cmd for ASADescription: If some boot images are already configured on an ASA device and you try to add another TFTP boot image, the deployment fails.
CSCsd58293—AAA servers discovered without a key do not use the global keyDescription: If you discover a AAA server without a defined key on a Cisco IOS router, Security Manager does not properly discover and implement the global key in place of the missing server-specific key.
CSCsd58953—Deployment error displays incomplete information about failureDescription: Deployment fails and the error messages that appear do not supply adequate information about the error.
CSCsd59527—ASA: AAA accounting mode and server port not discovered correctlyDescription: If you discover AAA servers configured on an ASA device, the group accounting mode is not defined in Security Manager with the default value and the server port is not defined according to the server protocol.
CSCsd59545—RADIUS AAA host key is changed by backoff exponential parameterDescription: Discovery of a router that uses the backoff exponential parameter as part of the definition of a RADIUS AAA host causes the correct key to this host to be overwritten upon deployment.
CSCsd60172—PIX/FWSM-Policies with nested network objects fail activity validationDescription: Activity validation fails on FWSM and PIX platform policies that contain network objects that refer to other network objects containing a single IP address.
CSCsd60698—PIX/ASA discovery creates AAA server groups with excessively long namesDescription: Under certain circumstances, Security Manager might generate a name for a AAA server group that exceeds the maximum length supported by firewall devices. Any policy that uses this AAA server group fails validation.
CSCsd60868—Device credentials erased in rollback instances in Config ArchiveDescription: Device Credentials that were once displayed in the Device Properties menu can disappear after you roll back to an earlier configuration from Configuration Archive. This can occur when previous deployment was to file, or when previous deployment contained empty delta configurations.
CSCsd62598—Discovery fails after you change the Default Source Ports settingDescription: Discovery fails after you change the Default Source Ports setting on the Policy Object page of the Security Manager - Administration window to Use Secure Ports.
CSCsd62633—PIX/ASA rediscovery does not add AAA servers to AAA server groupsDescription: Under certain circumstances, performing rediscovery on PIX/ASA devices does not add the AAA servers defined on the device to the related AAA server group.
CSCsd63562—Incorrect validation for xlate timeout on FSWM 2.3(3) deviceDescription: The minimum Translation Slot (xlate) timeout that you can set on the Timeouts Policy page is 30 seconds for FWSM 2.3(3) devices. However, Security Manager requires a minimum timeout of 1 minute.
CSCsd63938—FWSM interface table is empty and cannot be monitoredDescription: The interface table in the Failover policy for FWSMs in single transparent mode and security contexts in transparent mode contains no information. As a result, you cannot set these interfaces to be monitored.
CSCsd66712—url-block commands cause deployment to failDescription: If you are specifying web filter settings for PIX/ASA devices for the first time, deployment might fail when you send url-block commands.
CSCsd67225—LDAP subcommand for aaa-server is dropped for Tunnel Group deploymentDescription: A AAA Server host with LDAP protocol does not generate the subcommand "ldap-base-dn String" from Security Manager and the subcommand is removed from the device at deployment.
CSCsd67246—Job with multiple AUS-managed devices fails on first deploymentDescription: After you deploy configurations to multiple AUS-managed devices in a single job, deployment to some of the devices fails and a "CALLHOME-PARSER-INVALID_ELEMENT" message is recorded in the transcript.
CSCsd68099—Job state is "Deployed" although device is still deployingDescription: If a deployment job contains both CNS managed and non-CNS managed devices, deployment status might not accurately reflect the actual deployment status of all the devices in the job. For example, deployment status might be "deployed" before all the non-CNS managed devices have finished deploying.
CSCsd69875—The no shut command is not generated for IOS transparent firewall BVI1Description: If an IOS device does not have "bridge group 1 protocol ieee," "bridge 1 route ip," and "bridge irb" and you configure BVI1 IP address in both the interface UI page and Transparent Settings page, deployment fails.
CSCsd72206—Policy Query does not display the correct relationship for interfacesDescription: When source, destination, and service are in a policy query with no interface selected, and the source, destination, and service match rule values completely, the query and rule are deemed identical and the interfaces detail shows that "any" interface is identical to the rule interface value.
CSCsd73984—Policy Query not showing rule results in Policy viewDescription: If you are in Policy view and you query a rule with a service that is contained in a service group used in the rule, the query results are blank.
CSCsd75967—SQL error during installation of Security Manager with ACSDescription: During installation of Security Manager, a dialog box shows that an interactive SQL error occurred. This problem occurs if a Sybase database engine is running while you are installing Security Manager.
CSCsd76242—Logging message does not generate CLI to enable/disable a syslog messageDescription: Configuring the "Suppressed" setting for a syslog message on the Platform > Logging > Server Setup page has no effect when you deploy the configuration to the device.
CSCsd77059—Modify users in ACS mode cannot create/delete policies in Policy viewDescription: Under certain circumstances, users who have Modify permissions in ACS mode cannot create or delete policies in Policy view.
CSCsd78965—Rule might have incorrect rule number if logging option is offDescription: An incorrect rule number results if you paste or add a rule at the same place more than once and logging is turned off.
CSCse09955—Cannot create network/host object that refers to object with single IPDescription: When defining a policy that requires a single IP address, an error occurs if you create a network/host object that refers to a second network/host object on which the required IP address is defined.
CSCse10636—NAC-Missing validation for subinterfaces triggers deployment failureDescription: The deployment of NAC interface commands (eou max-retry and eou revalidate) fails on subinterfaces.
CSCse23468—Rollback of context fails due to certificate mismatchDescription: Rollback of a context fails because the device certificate was changed. On the next device operation, an error message states that the certificate is not trusted.
CSCse31816—AAA server cmd from IOS is not parsed correctly when reused by firewallDescription: If a AAA server discovered from an IOS device contains a leading "7" in its shared key and if the shared key is reused by a PIX/ASA/FWSM device, an error is issued on the key during activity validation.
CSCse33101—GUI notation "ASA" means user-input field applies to ASA and PIX 7.xDescription: The GUI adds notations next to user-input fields to indicate platform support. Currently, certain notations reference "ASA"; however, because the PIX 7.x platform uses the same software as ASA, the "ASA" notation applies to both ASA and PIX 7.x platforms (unless otherwise stated).
CSCse34675—Multimode: Rollback replaces the default config in the contextsDescription: When rollback of an admin context or another virtual context on ASA 7.0(5) multimode devices fails, it reverts to the factory default configuration instead of the device startup configuration.
CSCse43848—Deployment fails after upgrade if upgrade is installed on diff directoryDescription: A data upgrade from Security Manager 3.0 to 3.0.1 fails if you install Security Manager 3.0.1 on a new server and in a different directory when compared to the directory in which it was originally installed. This might lead to a deployment failure because referenced configuration files are not available under configuration archive.
CSCse48038—Certificate is not retrieved during upgradeDescription: After you upgrade and restore to Security Manager 3.0.1 from 3.0, any device operation produces an error message notes that the certificate is not trusted. This is because the certificate is not retrieved during upgrade.
CSCse50096—Failover - ASA/FWSM should not pop up bootstrap window if no changesDescription: For both ASA and FWSM, the Bootstrap window is always displayed even if no changes are made to the LAN Failover policy.
CSCse57548—ASA 7.1 incorrectly deploys shutdown LAN FO intf command againDescription: Deployment fails for ASA 7.1 devices configured with LAN failover in multi mode.
CSCse58530—Web Filter: Incorrect validation for having UDP with URL buffer memoryDescription: Deployment to a device might fail if a URL server with protocol UDP is defined along with the URL buffer memory.
CSCse58543—IOS: Deployment fails for UDP protocol with inspect HTTPDescription: If an inspection rule is configured with destination IP and protocol UDP, validation fails for UDP protocol with HTTP.
CSCse58554—Need validation for having aol as inspect protocolDescription: If an inspection rule is configured with "aol" as the inspect protocol on unsupported devices, a validation error results.
CSCse59578—Web Filter: Deployment fails for service port range in URL filterDescription: Deployment to a device might fail if two filter commands with the same source and destination addresses have overlapping service ports.
CSCse63692—Deployment fails on RA Catalyst 6500/7600 configured with FWSM and VRF-Aware IPSecDescription: In a remote access VPN, if you configure a Catalyst 6500/7600 device with a VRF-Aware IPSec policy and a FWSM blade, deployment fails due to the incorrect order of the CLI commands, which configure the FWSM blade before the VRF-Aware IPSec policy.
CSCse63971—Deployment fails after restore if upgrade is installed on diff directoryDescription: A restore operation of Security Manager 3.0.1 fails if you install Security Manager 3.0.1 on a new server and in a different directory when compared to the directory in which it was originally installed. This might lead to a deployment failure because referenced configuration files are not available under configuration archive.
CSCse70778—IOS: Transparent firewall deploy fails due to incorrect bridge group IDDescription: If bridge-group is configured on an IOS device and its ID is not 1, the deployment of the transparent policy fails.
CSCse78803—Invalid warning with parent policyDescription: An invalid validation warning might be issued about having an interface unbound to any access-lists.
CSCse78893—RADIUS and SDI deployment fails after upgrade to Security Manager 3.0.1Description: After you upgrade Security Manager from 3.0 to 3.0.1, deployment might fail for AAA RADIUS or SDI servers.
CSCse79118—FWSM 3.1(x) Failover cannot be deployed due to out of sequence commandsDescription: You will receive a deployment error if you make the following configuration changes for an FWSM 3.1(x) device and deploy those changes in the same deployment job:
–
Define VLAN interfaces.
–
Allocate the new VLAN interfaces to a security context.
–
Create an active/active or active/standby failover policy.
CSCse79127—Deployment fails after changing FWSM failover modeDescription: If you change the failover mode for an FWSM running 3.1(x) from active/active to active/standby or from active/standby to active/active, you will receive the error "DOWNLOAD OPERATION FAILED : 24410 : Error parsing the show config response: Command Ignored, Configuration in progress..." when you deploy to the device.
CSCse79359—Cannot create multiple contexts for FWSM 3.1(2) or 3.1(3) in single jobDescription: If you create multiple security contexts for an FWSM running 3.1(2) or 3.1(3) and deploy those security contexts in the same job, deployment fails with the error "DOWNLOAD OPERATION FAILED: 24410: Error parsing the show config response: Command Ignored, Configuration in progress..." for some security contexts and the error "DOWNLOAD OPERATION FAILED: 24015: IO error during SSL communication." for other security contexts.
CSCse79360—VLAN created in Security Contexts policy deleted on second deploymentDescription: If you modify the Security Contexts policy for a system context of an FWSM and reference a VLAN that does not exist in the Interfaces policy for the same system context, the VLAN is created on the FWSM when you next deploy to the system context. However, because the VLAN is not added to the Interfaces policy in Security Manager, the next time you deploy to the system context, the VLAN will be removed and any future deployments to virtual contexts that refer to that VLAN will fail because the VLAN is no longer defined in the system context.
Security Manager Known Problems
Catalyst 6500/7600 Configuration
Table 2 Catalyst 6500/7600 Configuration
CSCsi17582—Cannot change the data port VLAN running mode after negating CLI on IDSMDescription: Deployment fails when you attempt to change the running mode of the data port VLAN from Trunk (IPS) to Capture (IDS) from the IDSM Data Port VLANs dialog box and the following error message is displayed:
Command Rejected: Remove trunk allowed vlan configuration from data port 1 before configuring capture allowed-vlans CSCsi17608—Deployment fails when allowed VLAN ID is modified on IDSM capture portDescription: If you modify the allowed VLANs of an IDSM data port that has been configured as a capture port and deploy configurations to the device, the following error occurs:
"Capture not allowed on a SPAN destination port" CSCsi24091—Deploy fails if you change access to trunk mode & enable DTP negotiationDescription: Deployment might fail when you attempt to modify the physical port configuration type from access to trunk mode for a Catalyst switch and keep the Enable DTP negotiation check box selected in the trunk port mode.
CSCsi31232—Catalyst 6500/7600 chassis discovery fails after upgrade from 3.0 to 3.1Description: When you migrate a Security Manager 3.0 or 3.0.1 database to 3.1 in workflow mode, and try to discover the configuration of the upgraded Catalyst 6500 Series switch, Cisco 7600 Series router, or FWSM managed using the chassis before creating an activity, discovery fails.
Client Software
Table 3 Client Software
CSCsc91430—A blank error message is displayed when you update your client softwareDescription: During a service pack or point patch installation, a system prompt tells you to uninstall Security Manager Client. Unless you click the OK button, an error message that contains no text is displayed.
CSCsd39354—Some Windows users see no desktop shortcut or Start menu shortcutDescription: On a PC with many users, only the person who installs Security Manager Client can see the desktop and Start menu shortcuts that show that Security Manager Client is installed.
Configuration Archive
Table 4 Configuration Archive
CSCsi11419—Rollback fails 50 percent of the time with Failover enabledDescription: After rolling back Failover configuration to the device, the secondary unit does not come up automatically and does not participate automatically in the Failover setup.
Deployment
Table 5 Deployment
CSCsa84494—Discovery & view current config can't occur concurrently with deploymentDescription: Performing discovery or viewing the current configuration of a device while deployment is in progress might lead to unpredictable results.
CSCsc22934—ACL limitations on Layer 2 interfaces on IOS ISR devicesDeployment fails if access rules containing certain options are associated with Layer 2 interfaces of ISR routers.
CSCsd38578—Deploying to a device with no policies erases the config on the deviceDescription: The configuration on the device is erased if you deploy to the device before any policies have been defined in Security Manager.
CSCsd67440—Deployment fails after you restart the Daemon ManagerDescription: Deployment fails after you restart the Daemon Manager because the backend server process does not start.
CSCse10629—Deployment successful but not all delta commands deployed to deviceDescription: Deployment appears to be successful; however, not all of the commands in the delta configuration are deployed to the device.
CSCse23064—Enrollment URL CLI causes failure in deployment to AUS managed deviceDescription: Deployment to AUS-managed device fails if the deployment configuration contains the CLI command "enrollment url http:..."
CSCsi09797—Job state for completed jobs is "Deploying" for CNS-managed IOS routersDescription: After Security Manager successfully deploys the configuration file to CNS, and Cisco IOS routers configured for CNS poll and apply the configuration changes at the predefined polling period, the Status column in the Deployment Manager window continues to display the job state as "Deploying".
CSCsi18673—Security Manager deployment may trigger ObjectGroup name warningsDescription: Security Manager deployment details may show ObjectGroup name warnings. For example, ObjectGroup Netbios.udp is created from Policy Object Netbios. On networks with a large number of deployments this may cause an exceedingly large number of warnings, making it hard to monitor the deployments.
CSCsi18678—Security Manager deployment may trigger interface name warningsDescription: Security Manager deployment details may show name warnings of the sort: "Interface defined on device does not have a name." That is, some of the interfaces defined on a device do not have a defined name. Rules bound solely to these interfaces will not be deployed. On networks with a large number of deployments this may cause an exceedingly large number of warnings, making it hard to monitor the deployments.
CSCsi29146—Deployment using AUS fails after upgrade from 3.0 to 3.1Description: Security Manager deployment details may show 'Interface defined on device does not have a name' warnings if the interface name is empty. For example, some of the interfaces defined on a device do not have a name defined. Rules bound just to these interfaces will not be deployed.
CSCsi31224—Preview failed after deploying config to AUS serverDescription: A device's certificate is changed after retrieving the config file from the AUS server. The certificate stored in Security Manager would be out of sync with the device, hence cause the preview to fail with certificate mismatched error.
Device Management
Table 6 Device Management
CSCsc51908—Cannot add a system context from DCR into Security ManagerDescription: If you try to import a system context that belongs to a multi-mode PIX Firewall 7.0 or an ASA device from DCR to Security Manager, the import fails and an error message results.
CSCsc78319—Security Manager does not support changing the device type in DCRDescription: The device icon in the Device selector does not match the device type and the Policies selector displays only the Flex Config policy when you click the Device View button in the tool bar.
CSCsd49045—Unclear error message when IOS SSL deployment exceeds maximum sizeDescription: Deployment to Cisco IOS router fails when SSL is the transport protocol and you see a confusing error message.
CSCsd71001—Not able to import AUS device from DCRDescription: You cannot import an AUS-managed device from DCR to Security Manager.
CSCse70089—RBAC-Authorization and duplicate display name errors when adding devicesDescription: Authorization and duplicate display name errors occur when you add devices to a Security Manager server that uses Cisco Secure ACS for AAA.
Diagnostics, Monitoring, and Troubleshooting Tools
Table 7 Diagnostics, Monitoring, and Troubleshooting Tools
CSCsg13603—Device connectivity test takes a long time for unreachable devicesDescription: When you test device connectivity while adding devices using the Add Device from Network or the Add New Device wizard, the device connectivity test takes a long time to complete if the device cannot be reached.
CSCsi04942—IEV error while installing only Common Services 3.0.5 or AUS 3.1Description: When you install only Common Services 3.0.5 or AUS 3.1 from the Security Manager DVD, an IEV error message is displayed even if you did not select Security Manager 3.1 during installation.
CSCsi08390—IEV installation fails on systems without C: driveDescription: During installation of Security Manager server 3.1 on systems that do not contain C: drive, IEV server fails to install and an error message is displayed. Also, an error is logged in the server installation log file.
CSCsi27178—Several pages are blank in SDM 2.4 after discarding changesDescription: After you perform configuration changes for Cisco IOS devices using SDM 2.4 started from the Security Manager client and click Discard Changes to reset to the previously applied configurations, many of the pages are blank or empty.
CSCsi76604—Data archival does not work in IEV started from Security ManagerDescription: Database archival feature that enables you to archive real-time events does not work in IEV started from Security Manager. However, this problem does not occur on a system in which IEV is installed separately from Cisco.com and started outside of Security Manager.
CSCsi86335—Cross-launch of IEV client fails if Symantec application is runningDescription: You cannot start IEV client from Security Manager client on a system in which the Symantec Client Firewall Port Scanning Module or Symantec Secure Port application is running.
Discovery
Table 8 Discovery
CSCse27578—Discovery/deployment of multiple FWSM VCs hangsDescription: Discovery or deployment hangs for multimode FWSM with several virtual contexts.
CSCse99139—Rediscovery of inventory alone can create device-override building blocksDescription: Device level overrides for policy objects corresponding to object groups can be created after discovering only the inventory policies like interfaces.
CSCsi33347—Auto-update:Changing order of AUS servers does not generate commandsDescription: On a 7.2 ASA/PIX with multiple AUS servers, changing the order of the AUS servers does not generate any commands.
CSCsi45142—AAA - source intf disc from global cmd instead of aaa subcommandDescription: The interface parameter is not discovered for the AAA-server building block discovered from IOS routers.
CSCsi45204—QoS policy not discovered when WRED is enabledDescription: When Weighted Random Early Detection (WRED) is configured, discovery of an IOS device with a QoS policy fails to discover the QoS policy.
Firewall Services
Table 9 Firewall Services
CSCsa81103—Unable to create an access rule with TCP flagsDescription: Security Manager does not support TCP flag specifications, such as urg, fin, psh, and ack, in access rules. As a result, during discovery, Security Manager drops the specifications.
CSCsa81104—Unable to create an access rule to match QoS parametersDescription: Security Manager does not support ACE options such as DSCP, ToS, or precedence. As a result, during discovery, Security Manager drops the options.
CSCsa98978—Hit Count does not expand FWSM devices with object-group enabledDescription: Although the GUI allows you to enable the Object Group Search option for FWSM devices, the FWSM does not expand object groups when listing access rules after a "show access-list" command and Hit Count results are inaccurately displayed.
CSCsb85487 —Need warning when ACL deployment to IOS devices can cut off accessDescription: Security Manager does not check if the firewall rules that you configured in Security Manager permit management traffic (SSH and HTTPS) to the IOS device being managed. As a result, after firewall rules are deployed to the device, connection to the device might be lost.
CSCsc81905—QIT: Empty ACL is deployed on 87x series routers for BGP portDescription: IOS 87x ISR routers do not support BGP as a routing protocol or as a service in ACLs when the device has only 24 MB of memory; however, BGP is supported when the device has more than 24 MB memory. Security Manager does not detect the amount of memory available on the device and cannot enforce any restrictions. As a result, job deployment containing an ACL with ACEs having BGP will fail.
CSCsc84443—IP HTTP server cli is not removed after the policy is unassignedDescription: IOS devices require that HTTP is used as the traffic type for authentication proxy, which generates the command ip http server. Security Manager does not remove the CLI when authentication proxy is unassigned from the device in Security Manager.
CSCsc85416—User configured AAA/AuthProxy CLIs are not removed from the deviceDescription: If an AuthProxy configured on an IOS device has a user-specified name that does not comply with the naming convention used by Security Manager, the name is not removed if the device is discovered and the policy is unassigned.
CSCsc87646—Deployment to IOS device fails if AuthProxy is assigned to L2 interfaceDescription: If you create AAA or inspection rules for "all" interfaces on an IOS device, deployment fails if the device is using Layer 2 port.
CSCsd26482—IOS "access-list" Standard ACL is not supported by Hit CountDescription: IOS devices use standard ACLs for filtering; however, standard ACLs are not recognized when Hit Count reports are generated.
CSCsd30481—PIX 6.3: needs warning for the Time Range object in access rulesDescription: When you create an access rule for a PIX 6.x device, you can specify a time range in the GUI; however, the device does not support the time range feature in the ACE and no warning is displayed during activity validation or deployment.
CSCsd33025—Deployment fails on a device with too many AAA server groupsDescription: If Security Manager tries to deploy AAA server groups to a device that already has the maximum number of AAA server groups, deployment fails.
CSCsd60788—No port-map command generated if rules and predefined protocols conflictDescription: IOS inspection port-map commands are not generated if inspection rules configured in Security Manager conflict with port definitions of predefined inspection protocols.
CSCsg35578—Import ACE: Validation not done if the config is not in show run formatDescription: Some options are omitted from rules that are created using the Import Rules tool, for example, empty port values and destination port values that are not validated for 'eq' and 'neq' for IOS devices.
CSCsh64420—Deployment fails modifying ACE in AAA ACL on FWSM3.1.1Description: For FWSM3.1(1) context, if you modify the AAA rules table, then deploy the change to the device, you might get the following deployment error:
ERROR: Unable to find AAA ACE Error acl_updated: aaa_acl_changed failed ERROR: Unable to delete ACE from dependent modules CSCsh68101—Activity Report: Issues with access rules tableDescription: Rule section changes are not reported in the activity reports.
CSCsh94210—Problems matching interface when reusing AAA policy objectsDescription: AAA Server policy objects cannot be reused because of mismatched interfaces. This might result from an interface role used to define an interface that is not matched to a physical interface after rediscovery. For PIX/ASA7.x devices, this might result from using "inside" (or an interface name that starts with "inside") to describe the interface.
CSCsh96644—FWSM ACL remarks may cause inline editing manual commit failureDescription: Deploying to FWSM 3.1(4) fails with an error saying "Specified remark does not exist" in the deployment transcript. This happens only when the "Let FWSM decide when to compile access-list" admin setting is unchecked and the access policies contain a number of comments.
CSCsi11697—Deploy fails after rollback operation followed by URL filter changeDescription: When you use Security Manager to roll back an ASA 7.2(2) device to a configuration that contains default inspection class-map and policy-map "global_policy". If you change Web Filter rules, then deploy the change, the deploy operation might fail.
CSCsi16937—FWSM: Need validation for non-standard netmask in address poolDescription: Deployment might fail if an IP address is configured with a non-standard mask for an address pool. Although the UI allows it, the only device version that allows non-standard masks is PIX/ASA 7.2+.
CSCsi18871—PIX 7.1 gtp-map subcommand order is not preservedDescription: Changes to the match-condition order for a gtp-map used in a PIX 7.0 or PIX 7.1 device do not get deployed to the device.
CSCsi23683—Deployment fails when you reconfigure bridge-groups in transparent rulesDescription: When you associate interfaces with another bridge-group and provision it in Security Manager, the deployment shows an error; however, the device in this case has been provisioned correctly.
CSCsi23773—Always generates range CLI for TCP mapDescription: If TCP Map is assigned in the "IPS, Qos and Connection Rules" then redundant tcp-options commands might be generated even if no changes are made to the TCP Map or related policy.
CSCsi27421—Deploy removes ACEs when creating ObjectGroup disabled for FWSM 3.1(3-4)Description: If an access-list entry (ACE) with an object group is internally expanded into a number of ACEs and if one of the expanded ACEs is inserted into the access-list, FWSM 3.1(3)12 and later rejects this ACE with an error "found duplicate element".
CSCsi34298—Webfilter: Deployment fails if overlapping filter commands are definedDescription: If two filter commands of the same type are defined with the same port ranges (service) or overlapping port ranges and overlapping networks, deployment to a device fails. The device does not accept overlapping filter commands.
CSCsi35479—HTTP policy: Commands generated for every deploymentDescription: For ASA 7.2 HTTP Maps, if the body match maximum is set to 0 (zero), the device accepts the command as "body-match-maximum" but shows it in show run as "body-match-maximum 0". This causes the delta to always contain the removal of the http policy-map subcommands and adding them back.
CSCsi49748—Transparent rules not removed from device when deleted in Security MgrDescription: If you delete the transparent firewall rules from Security Manager and deploy to the device, the rules are not removed from the device; however, Security Manager continues to show those rules as deleted.
CSCsi49794—AclNamePreserv: Deploy fails due to diff source addr in delta for staticDescription: When you change an access list that is shared between a static command and another command, deployment to the device might fail.
CSCsi50493—DataLoader's load method needs to handle quotesDescription: The access rules table might not finish loading for a newly discovered device if the discovered configuration has access-list remarks that contain quotes or double quotes.
CSCsi51974—Hit Count: Disabled for inherited rulesDescription: The Hit Count option, which is accessed from the Tools menu that is located below the Access Rules table, is disabled when you select access rules that belong to an inherited policy.

