Bug ID 1051237: ASM initial configuration script fails after upgrade

Last Modified: Jan 20, 2023

Bug Tracker

Affected Product:  See more info
BIG-IP ASM, Install/Upgrade(all modules)

Known Affected Versions:
16.1.0, 16.1.1, 16.1.2, 16.1.2.1, 16.1.2.2, 16.1.3, 16.1.3.1, 16.1.3.2, 16.1.3.3

Opened: Sep 30, 2021
Severity: 3-Major

Symptoms

After upgrading the system, the ASM initial configuration script fails with below error message: asm|INFO|Sep 23 22:34:07.480|16920|,,01070265:3: The ASM policy (/Common/test) cannot be deleted because it is in use by a API Protection Profile (/Common/test). asm|INFO|Sep 23 22:34:07.507|16920|,,failed to initialize

Impact

UCS loading or upgrade fails

Conditions

-- ASM security policy exists which is referenced by an API Protection Profile -- Upgrade or load a UCS with such a configuration onto a device where ASM is not yet provisioned

Workaround

On a freshly installed device (installed with liveinstall.saveconfig and liveinstall.moveconfig disabled) Provision ASM, wait for the device to become Active Load (using TMSH) the UCS file

Fix Information

None

Behavior Change