Has anyone else tried installing the latest patch with multiple virtual sensors with multiple sig configurations, event action rule configurations? I have been fighting this for a couple of days now. What I have found is that any sig/rule configurations other than the default sig0/rules0 are completely deleted by the upgrade. The virtual sensor configuration is kept, meaining that the sensor continues to try to use a sig/rule config that no longer exists.
This does not make for a happy sensor.
I am just curious if this is specific to what we are doing or if others have come across this.
To get a clearer picture of what I am trying to accomplish.
On one physical sensor, with multiple interfaces, I will have 2 virtual sensors.
Call the first one Outside
It will use custom signature config of OUT
It will also use custom event action rule of OUT.
The second one is IN
It will use custom sig config of IN
It will also use custom even action rules of IN.
These are both different than the default witch is called sig0 and rules0.
When the upgrade is performed, everything but sig0 and rules0 are deleted.
The virtual sensor configuration is still set to use the custom sig and rules, however they are no longer there.