Description

An administrator is trying to make changes to a policy template, but the changes are not commited, even though no warning is given. This article explains the problem and suggests a solution.

Symptoms

After making a change to a policy template, either within an IPS or Exempt rulebase, the changes will commit without showing an error, but will not be present when the commit is completed.

Solution

The reason for this behavior is that while it was previously possible to edit policy templates, since May of 2014 this has changed. Since that date, policy templates cannot be edited.

The solution is to make a copy of the policy template, and then edit it:

root@SRX1# copy security idp idp-policy Recommended to idp-policy New_Recommended

{primary:node0}[edit]
root@SRX1# show | compare
[edit security idp]
+ idp-policy New_Recommended {

For more information on the policy template changes, please see the following Knowledge Base entries:

KB29111 - [SRX Series] Updated IDP policy templates [juniper.net]

TSB16412 - Juniper updating built-in IDP policy templates in attackDB update [juniper.net]

Related Information