Bug ID 1051237: ASM initial configuration script fails after upgrade

Last Modified: Jun 28, 2025

Affected Product(s):
BIG-IP ASM, Install/Upgrade(all modules)

Known Affected Versions:
16.1.0, 16.1.1, 16.1.2, 16.1.2.1, 16.1.2.2, 16.1.3, 16.1.3.1, 16.1.3.2, 16.1.3.3, 16.1.3.4, 16.1.3.5, 16.1.4, 16.1.4.1, 16.1.4.2, 16.1.4.3, 16.1.5, 16.1.5.1, 16.1.5.2, 16.1.6

Opened: Sep 30, 2021

Severity: 3-Major

Symptoms

After upgrading the system, the ASM initial configuration script fails with below error message: asm|INFO|Sep 23 22:34:07.480|16920|,,01070265:3: The ASM policy (/Common/test) cannot be deleted because it is in use by a API Protection Profile (/Common/test). asm|INFO|Sep 23 22:34:07.507|16920|,,failed to initialize

Impact

UCS loading or upgrade fails

Conditions

-- ASM security policy exists which is referenced by an API Protection Profile -- Upgrade or load a UCS with such a configuration onto a device where ASM is not yet provisioned

Workaround

On a freshly installed device (installed with liveinstall.saveconfig and liveinstall.moveconfig disabled) Provision ASM, wait for the device to become Active Load (using TMSH) the UCS file

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips