Troubleshooting problem when cannot create SAM rule via CLI Technical Level
  • Adding Suspicious Activity Monitoring (SAM) rules via CLI fails with error:
    [Expert@MyHost:0]# fw sam -f MyHost -t 600 -l long_noalert -J src
    sam: MyHost (0/1) failed 'Inhibit Drop Close src ip on MyHost' processing
  • The output of "fw sam -M -nji all" does not show the new SAM rule.
