CFS pending activation warning reported in Portal despite no policy changes made
search cancel

CFS pending activation warning reported in Portal despite no policy changes made

book

Article ID: 271751

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Client Firewall Service (CFS) enabled and includes a number of non default policies.

Internal change control process followed when any CFS policy changes are applied.

With no recent policy changes applied, Cloud SWG admin noticed that there are apparent policy that need to be committed - there is an * next to CFS-G2 where we added rules.

Why would we report that changes need to be 'activated' when no changes were made?

Environment

Client Firewall Service.

Cloud SWG.

Cause

A comment was added to a rule, without any changes in the actual policy.

Resolution

Two options exist to address this issue for now.

  • remove the comment and refresh the page (will undo pending change request). Also a good way of confirming no policy changes were applied.
  • apply the update to remove the pending change.

Additional Information

All Portal admin changes are logged to the audit logs.

In the above scenario, we clearly saw that there were no policy changes between the last 'update' operation with CFS (which applied all the 'saved' operation rules) and the pending request.

Adding a comment to a rule does not trigger a 'save' operation to the audit logs, but does confirm that no policy rules were updated.

Broadcom is planning a Portal update that will NOT trigger a policy change event when a command is added to an existing rule.