Defense Policy Deployment Fails
Symptom
On the page displayed after you click the Defense tab and choose Policy Settings > Zone in the navigation tree, the system prompts a deployment failure after you select a Zone and click Deploy.
Possible Causes and Troubleshooting Procedure
- The NE goes offline.
- Telnet/SSH parameters on the NE are incorrectly configured.
- A Zone with the same name or ID already exists on the NE.
- The version of the NE does not match with that of the ATIC management center.
- The NE is upgraded, after which the NE version is not synchronized on the ATIC. As a result, the version recorded on the ATIC is inconsistent with the actual NE version.
The troubleshooting procedure is as follows:
- Check whether Telnet/SSH parameters on the NE are correct. If yes, go to the next step.
- Check whether the error message is ID conflict. If no, go to the next step. If yes, check whether a Zone with the same ID exists on the NE, as shown in the following figure.
Place the cursor on the Zone name and view the information displayed on the lower left of the browser. The digit in the calling method is the Zone ID delivered to the NE. As shown in the following figure, 11 is the Zone ID.
Log in to the NE and check whether a Zone with the same ID exists.
If yes, run the display ddos-zone command to display the name of the Zone IDed 11.
Disable this Zone or modify the Zone ID. Then try to perform the deployment again.
- Check whether the error information is that a Zone with the same name already exists on the NE. If no, go to the next step. If yes, run the display ddos-zone [zone-name] verbose command in the system view to check the Zone configuration on the NE. After locating the Zone with the same name, disable it and then try to perform the deployment again.
- Click the Defense tab and choose Network Settings > Devices in the navigation tree. View the software version of the device, as shown in the following figure.
Check whether the software version is consistent with the actual version. If no, perform NE synchronization. After the synchronization succeeds, try to perform the deployment again. If yes, go to the next step.
- If the fault persists, contact Huawei engineers.