Loading...
Loading...
Within a high availability (HA) pair of Secure Firewall Management Centers (FMCs), the active FMC of the pair may not generate correlation events for certain active correlation rules. If the affected correlation rules have any responses assigned to them in an active correlation policy (for example, sending out a syslog alert with the contents of the correlation event), the active FMC will not put the responses into action.
FMCs are in HA. A correlation policy has been configured with at least one correlation rule. The correlation policy is active. At least one rule employed by the correlation policy contains a condition of "Access Control Rule Name" with either "contains the string" or "is" as the operator, with the exact/partial name entered into the field for this condition matching the name of at least one actual access control rule configured within the access control policies present on the FMC. The types of events for the correlation rule that can have "Access Control Rule Name" as a condition: * intrusion * connection A switch of FMC operating roles (active vs. standby) has occurred between the FMCs in HA since the most recent time the correlation policy (and/or any of the rules employed by the correlation policy) was saved (any action that will organically regenerate /etc/sf/compliance.rules on the FMCs).
On the GUI of the active FMC, open the affected correlation policy for editing (Policies > Correlation > Policy Management). Then, without making any changes, save the correlation policy. This will ensure that at least the active FMC will generate correlation events based on matches to the affected correlation policy.
The documented behavior for responses to matches on correlation rules (where responses may only happen upon the generation of a correlation event) with FMCs in HA is that the response should only happen on the active FMC -- meaning that the response (for example, sending out a syslog alert with the contents of the correlation event) should not happen on the standby FMC.
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.