Description

You may need to assign a policy in Juniper Security Director Cloud if:
 

  • A new policy is created for the device and you imported the policy again.

  • The existing policy is obsolete.

  • The policy was updated directly on the device and you imported the policy again.

  • The policy was not deployed after it was imported from the device.

Symptoms

When you import a new policy and assign, deploy job fails with the below error:

Error Type: Application Error
Error while converting rule: test of Policy: vSRX22-1. Error message: Could not deploy vSRX-1. To deploy vSRX-1, you will need to deploy both vSRX22 and vSRX.
Reason: Device needs to be unassigned from vSRX to be successfully assigned to vSRX-1.

 

Solution


Error Type: Application Error
Error while converting rule: test of Policy: vSRX22-1. Error message:

The above error message is generic so the user needs to check the message in the Error message field above and try to fix it.


After you reassign all devices in a policy to a different policy or import the device policy, you must deploy both policies simultaneously to delete the old policy.

As per the error mentioned in the Symptoms field:

To deploy vSRX22-1, you will need to deploy both the old and newly imported policies, i.e., vSRX-1 and vSRX. So select vSRX-1 and vSRX policies and click on deploy.

The device must be unassigned from vSRX22 to be successfully assigned to vSRX22-1.

 

Modification History

2024-15-04: New Article
2024-01-05: Added generic error message

Related Information

https://www.juniper.net/documentation/us/en/software/sd-cloud/sd-cloud/topics/task/sd-cloud-cp-firewall-policy-editing-cloning-deleting.html