Pre-requisites:
- FMOS version is in the 8.25.x release line
***********************************************************
Skipping normalization for rule with config state not 'deployed'.
The above may indicate that the Policies on the CSM have been committed but not deployed to the child devices.
You can also confirm if this is the case by examining the Unified ACL file located in the support files from one of the Cisco devices. The below line will provide what state the config is in:
<configState>committed</configState>
Per the Cisco CSM documentation "committed" policies are ones that have not actually been deployed to the device in question, only saved.
We do not normalize any acls that have a config state other than "deployed". We do not "fall back" to the local access-list file if nothing is normalized from the CSM unified-acl, because that is the purpose of the Unified CSM Normalization. When Unified CSM Normalization is selected we normalize from the package that the CSM has for the device.
Comments
0 comments
Article is closed for comments.