ProxySG & Advanced Secure Gateway

 View Only
Expand all | Collapse all

ASG AV&Malware Databases Critical

  • 1.  ASG AV&Malware Databases Critical

    Posted Jan 09, 2020 02:52 AM

    Hello, Our ASG Health check warning.Because cas.bluecoat-local-response Check failed And ASG's Content Analysis Kaspersky Labs can't update. We try to restart the ASG ,restart content analysis web management.But the issue still exists. Now this issue makes ASG's Content Analysis can't block objects



  • 2.  RE: ASG AV&Malware Databases Critical

    Posted Jan 09, 2020 11:48 AM
    Hi, Verify that the ASG is allowed to access the required URLs on your Firewall and/or Proxy. https://support.symantec.com/us/en/article.tech243261.html Or allow this url from Firewall make sure to bypass from ssl interception too. support.symantec.com shasta-clt-symantec.com abrca.bluecoat.com api.us.dmas.symantec.com remote-support.bluecoat.com stnd-ipsg.crsi.symantec.com frs.es.bluecoat.com sp.cwfservice.net contentanalysis-ma.es.bluecoat.com liveupdate.symantec.com subscription.es.bluecoat.com device-services.es.bluecoat.com services.es.bluecoat.com bto-services.es.bluecoat.com maa-updates.es.bluecoat.com validation.es.bluecoat.com upload.bluecoat.com mft.symantec.com ent-shasta-rrs.symantec.com wpa.one.microsoft.com appliance.bluecoat.com virustotal.com


  • 3.  RE: ASG AV&Malware Databases Critical

    Posted Jan 10, 2020 01:23 AM
      |   view attached

    Hi Aboonaim

    We have confirmed that all URLs are allowed on the firewall for ASG.

    When I use ASG's Content Analysis test file, I also find that the CA reports CODE “ICAP/1.0  500 Server error ” 

    Antivirus_engine_error

    How can i fix this... Thanks

     

     



  • 4.  RE: ASG AV&Malware Databases Critical

    Posted Jan 10, 2020 03:55 AM
    Dear Wenji, What is your SGOS version? Local CAS service should not failed


  • 5.  RE: ASG AV&Malware Databases Critical

    Posted Jan 11, 2020 01:25 AM

    Dear Aboonaim

     

    Our Proxy Version: SGOS 6.7.3.8

    Can this problem be solved by upgrading the version?

    These days I try to open a case but no one responds. This problem has been bothering me.

    Thanks for your patience,Aboonaim



  • 6.  RE: ASG AV&Malware Databases Critical

    Posted Jan 11, 2020 01:37 AM
    Hi, Can you share me Pcap from your device with filter host contentanalysis-ma.es.bluecoat.com or host liveupdate.symantec.com or host subscription.es.bluecoat.com. Also share me Sysinfo of your device. Https://x.x.x.x/8082/sysinfo


  • 7.  RE: ASG AV&Malware Databases Critical

    Posted Dec 01, 2020 02:21 PM
    Hi Wenjl, Could you please let us know if your issue fixed. as we are getting the same.


  • 8.  RE: ASG AV&Malware Databases Critical

    Posted Dec 02, 2020 01:29 PM
    Hi All,

    We are getting the same issue too, after contacting the support they observed that the CAS disk is Full, that's why the CAS database was not updated. They recommended to (reboot the system with r option) because there is no other way to clear the disk!

    Still we did not do rebooting!  I am looking for another way that may helps!
    Thanks
    Jalila


  • 9.  RE: ASG AV&Malware Databases Critical

    Posted Dec 10, 2020 01:09 PM

    Hi all,

    We are experiencing the same issue, but only with one of our appliances (currently running 2).

    Also told to reboot and manually apply license. Reboot did nothing and the manual license application failed. I think there is an issue with the licensing server potentially post migration that happened? Or did it move and they didn't tell any of us, leading to these issues?

    Also disappointed with raising any tickets, little to no response.

    Version:ASG 6.7.5.3
    Model:ASG-S400-30




  • 10.  RE: ASG AV&Malware Databases Critical

    Posted Dec 14, 2020 02:53 AM
    We are having the same issue, we work with ASG 6.7.3.14, last information from technical support ist that is a problem with the CAS Version in the asg, and maybe the only option is to upgrade to a newer release for example 6.7.4.9

    Regards

    Fermin

    ------------------------------
    Sytems Engineer
    GW
    ------------------------------



  • 11.  RE: ASG AV&Malware Databases Critical

    Posted Dec 24, 2020 07:37 AM

    We are facing the same error and i opened a ticket with vendor with no answer, can you please assist for the same to be solved. 




  • 12.  RE: ASG AV&Malware Databases Critical

    Posted Dec 29, 2020 08:08 AM

    it seems this issue is not yet solved because no one replied for the solution. 




  • 13.  RE: ASG AV&Malware Databases Critical

    Posted Jan 07, 2021 01:17 AM
    Hello Ahmed,
    i was on vacation, the only solution was the upgrade to a newer release, we had the 6.7.3.14 then i am working with 6.7.4.13.
    the upgrade path was from 6.7.3.14 to 6.7.4.3 then 6.7.4.13

    Regards

    Fermin

    ------------------------------
    Sytems Engineer
    GW
    ------------------------------



  • 14.  RE: ASG AV&Malware Databases Critical

    Posted Feb 16, 2021 06:56 AM
    Hi Guys,

    I face the same issue with ASG s400-20 running 6.7.5.8 code. We had the issue with 6.7.4.13 and support asked us to upgrade. We got the same issue even after upgrade. Was there any permanent fix for this issue.

    Thanks and Regards
    Shabeeb



  • 15.  RE: ASG AV&Malware Databases Critical

    Posted Feb 16, 2021 07:05 AM
    hi,


    I too running the same version and having same issues.





  • 16.  RE: ASG AV&Malware Databases Critical

    Posted Feb 16, 2021 09:14 AM
    Hello Shaikh,

    If this a space issue on the CAS part of the ASG, then you will have to restore to factory defaults using the "r2 option during bootup.As a matter of interest, do you have any forwarding rule in place in the policy.

    Regards
    Paul


  • 17.  RE: ASG AV&Malware Databases Critical

    Posted Feb 16, 2021 11:05 AM
    Yes we have 





  • 18.  RE: ASG AV&Malware Databases Critical

    Posted Feb 17, 2021 01:05 AM
    Hi all,

    We had the same issue, just we restarted/rebooted the system, the disk space was cleared and CAS error gone. as below:

    #(config)restart mode hardware
    #restart regular

    Don't forget to take the backup of the system to avoid any failure.
    Hope it helps.