Application Still showing up after removal from Security Rule

Reply
Highlighted
L3 Networker

Application Still showing up after removal from Security Rule

I recently added the ms-lync-online app to a rule in my PA-500.  We decided we didn't need it and removed it.  After a month of commits and saves that app is still showing up in the commit window summary and asking for a required app with it.  I have checked everywhere and that app is not part of any rule but the PA unit still thinks it is.  Any ideas how to clear this.

L7 Applicator

Re: Application Still showing up after removal from Security Rule

Hello Sir,

While you are applying a commit on this firewall, it should show the "rule name" along with the warning messages.

Example:: Rule 'XYZ' application dependency warning:

Application 'ms-lync-base' requires 'kerberos' be allowed, but 'kerberos' is denied in Rule 'DenyAny'

Application 'ms-lync-base' requires 'sip' be allowed, but 'sip' is denied in Rule 'DenyAny'

Application 'ms-lync-base' requires 'soap' be allowed, but 'soap' is denied in Rule 'DenyAny'

  

Could you please verify that rule once. If that rule is not having an application "MS-LYNC" added, then do a "commit force" from CLI else, Deactivate that rule >>> commit and activate again >>> commit.

Hope this helps

Thanks                                                         

L4 Transporter

Re: Application Still showing up after removal from Security Rule

Hello MemphisBrothers,

We can commit the whole config and just not the differential config. This is how we do.

configure

commit force

Once this is done can you test if you still see this.

If still seen can we do config Audit for the latest 2 config versions ( ALL for the lines ) and search for keyword ms-lync-online.

OR

Also we can export the running configuration to a xml file and do search for the keyword ms-lync-online.

These should resolve or direct the resolution.

L3 Networker

Re: Application Still showing up after removal from Security Rule

It does.  I just didn't get that part in the copy.  I did remove it from the attached rule.  The message is erroneous. 

L7 Applicator

Re: Application Still showing up after removal from Security Rule

Hello,

You can try with "commit force" from CLI.


Else, Deactivate that rule >>> commit and activate again >>> commit.


Thanks

L3 Networker

Re: Application Still showing up after removal from Security Rule

Tried the commit force in CLI.  No good.  Still showing up.  How do you export the config to XML?

L4 Transporter

Re: Application Still showing up after removal from Security Rule

Below is the image explaining where to go and how to export config file. They get exported as xml as they are in the format of xml.

exp.PNG.png

L3 Networker

Re: Application Still showing up after removal from Security Rule

I was able to open the current config in XML and did a search for ms-lync-online.  No matches found.  This is looking like a bug

L7 Applicator

Re: Application Still showing up after removal from Security Rule

Have you tried deactivating that rule >>> commit and activate again >>> commit.

L3 Networker

Re: Application Still showing up after removal from Security Rule

Cannot do this until late at night after bus, hours

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!