Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Firewall Policies reordering error

This thread has been viewed 2 times
  • 1.  Firewall Policies reordering error

    Posted Nov 18, 2015 02:51 PM

    Hey Airheads,

     

    I've run into an issue in which I receive the following error whenever attempting to reorder firewall policies, found here: Configuration > Access Control > User Roles

     

    firewall rules error Aruba clearpass.jpg

    I've never seen this error before, and haven't been able to search and find anything on this. Please let me know if you have any information on said error. Thank you!



  • 2.  RE: Firewall Policies reordering error

    EMPLOYEE
    Posted Nov 18, 2015 02:52 PM
    After creating the role, click Apply. Then go back into it and add your firewall policies.


  • 3.  RE: Firewall Policies reordering error

    Posted Nov 18, 2015 03:42 PM
    Hey Tim,

    This happens when I editing an existing policy, not when I'm creating a new one. All I'm trying to do is reorganize the policy order.

    Thanks,

    Ryan Hadley

    Sent from my iPhone.


  • 4.  RE: Firewall Policies reordering error

    Posted Nov 18, 2015 03:37 PM
    You can't change the order the AppRF / DPI rules are (1 and 2) , so anything you place will be under that and it will be rule 3


  • 5.  RE: Firewall Policies reordering error

    Posted Nov 18, 2015 03:45 PM
    Hey Victor,

    The policies were user created, not system generated.

    Thanks,

    Ryan Hadley

    Sent from my iPhone.


  • 6.  RE: Firewall Policies reordering error
    Best Answer

    Posted Nov 18, 2015 04:12 PM

    According to the error you are getting is because you are trying to place a rule on top of the AppRF rules

    Screen Shot 2015-11-18 at 4.06.42 PM.png

    You won't be able to move the "global-sacl" and the "Apprf-<ROLE-NAME>-sacl"

     

    For example in this role I can't move the allowall above those other two rules.

    So your first rule will have the position #3 for any user-role. 

     

    If you are trying to place your rule on any position other than 1 or 2 and is giving you that error then you may need to open an Aruba TAC case.

     

     



  • 7.  RE: Firewall Policies reordering error

    Posted Nov 18, 2015 10:27 PM

    Thanks, Victor. This ended up being the right solution. I guess it's a 6.4 thing. I got used to being able to reorder everything around how I wanted it, so I'll mess with this and move some of the stuff from the sacls into other policies.

     

    Thanks again.