After modifying Secure Web Filter policies, device goes into a sync-suspended state with error of 'Networks'
Affected Platforms - all
Affected Releases - all
- Upgrade to NCOS 7.21.40
Workaround to avoid failure condition:
When adding a new category in group configuration, also add a reference to that category in each policy. Then policies can be deleted in group configuration without issue. See "Additional Information" for details on this process.
Workaround to recover from failure condition:
Remove offending device-level configuration. This can be achieved by either:
- Clearing the device-level configuration via NCM -OR-
- Deleting the offending configuration using the API (Patch delete of webroot policies)
Steps to avoid this failure condition:
- In the group configuration, add a custom category.
- In the Web Filter Policies section, edit each policy to reference the new custom category:
- if the custom category is a allowlist, verify the action for the custom category is "Allow" (default action). Then click "Save" in the policy and then "Save" in the general Cloud-Based Filtering/Security section.
- if the custom category is a blocklist, verify the action for the custom category is "Block". Then click "Save" in the policy and then "Save" in the general Cloud-Based Filtering/Security section.
######################
Steps to create this failure condition:
- Create a group with two CPSWF policies.
- Move a device into that group; device now has both policies.
- In the group configuration, add a custom category; wait for device to sync.
- In the group configuration, delete policy two.
- Device will become "Sync Suspended" in NCM