Software Secure Workload
Activity Configure

Caveats

Host Firewall Backup

When enforcement is enabled for the first time in an Agent Config Profile, the agents running on AIX hosts, before taking control of the host firewall, store the current content of ippool and ipfilter into /opt/cisco/tetration/backup. Successive disable or enable transitions of enforcement configuration do not generate backups. The directory is not removed upon agent uninstallation.

Unload the existing IPFilter

When enforcement transitions from off to on, if the non-Cisco IPfilter package is already installed on the host, the agent will replace the IPfilter kernel extension with the Cisco IPfilter kernel extension and uninstall the non-Cisco IPfilter package.

Upgrade Cisco IPFilter

When a new version of the Cisco IPfilter is released, the Secure Workload agent will upgrade the system during the process of transitioning enforcement from off to on.


 

Upgrades must be performed when agent enforcement is turned off, as it may disrupt traffic if enforcement is on.