Commit Warning for Antispyware

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Commit Warning for Antispyware

Hi guys,

Trust all is well. After the firewall upgrade to version 10.2.1/ 10.2.2, we are getting the following errors after each firewall. Changes/commits are executed successfully. And everything seems to be working without problems.

 

Warning: spyware-profile AntiSpy-Alarm-Only(id: 251) is considered duplicate of AntiSpy-D(id: 258)
Warning: spyware-profile AntiSpy-Block-IP(id: 252) is considered duplicate of AntiSpy-D(id: 258)

Any idea?

 

Thank you in advance.

7 REPLIES 7

Cyber Elite
Cyber Elite

If you look at the firewall is the profile AntiSpy-D actually visible in the GUI or the CLI? I'd see if you actually utilize that profile in your configuration at all or not, and if you don't I'd just remove it as it seems likely that this was a configuration migration error when you upgraded. 

Hi BPry,

Thank you for your reply. The three Spyware profiles are being used under many security rules and it is not possible to delete one of them. We also created a dummy Spyware profile to no avail. Warnings are still present.

Community Team Member

Hi @Hamid.Saffarzadeh ,

 

Root cause for this issue might be because configuration details of two profiles are exactly same, the profiles will be identified as duplicate ones.

This is considered a cosmetic bug and will not interfere on operational level. Targeted to be fixed in PAN OS 10.2.4 but please reach out to support to confirm if you're hitting this exact same bug.

 

Cheers,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hi team,

I have just got a confirmation on the fix. It will be included in the PAN-OS 10.2.4.

Cheers,
Hamid

L5 Sessionator

Hi all,

 

Hamid, have you got bug ID for this issue ?

 

Rgds

Vincent

L5 Sessionator

Just got info: ref PAN-194988 target to be solved in Version 10.2.4.

L3 Networker

We are facing the same issue after upgrading to 10.2.3
But in our case the Spyware profiles do not match.
Spy-Alert-Only = crit,high,med to Alert (rest is default)
Spy-Outbound ) crit,high  to reset-both / med,low,inf to Alert

So the profiles are not the same, but still we get the working that our Alert Profile is a duplicate of our Outbound.
Is that also expected buggy behaviour 

 

Cheers

Alex

There's no home like 127.0.0.1
  • 6277 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!