299002 - ACL Configuration Is Incomplete
Agent error code #299002 means the knoc does not name the object the agent is meant to write the granted address into. The agent stops before contacting the device, because there is nothing on the device for it to change.
The message names which setting is missing. Which setting that is depends on the backend:
- Sophos SFOS: the IPv4 host group, or the IPv6 host group. Each address family goes into its own group, so a knoc that names only one of them can grant only that family.
- Sophos UTM: the network group reference.
- Cisco Firepower: the network group.
- SonicWall: the IPv4 address group, or the IPv6 address group. As with SFOS, each family has its own group, and a knoc that names only one can grant only that family.
- AWS: the region the security group is in.
- Google Cloud: the project the firewall rule or security policy is in.
- Cisco Meraki: the organization the policy object group is in.
This is not a device fault and not a transient one. Retrying the grant produces the same result until the knoc is edited.
Revoking is usually unaffected. Where the agent can withdraw access without knowing the group, it does, so existing access still expires and can still be revoked on a knoc that reports this code for new grants. AWS, Google Cloud and Meraki are the exceptions: every call names the region, project or organization, so without one the agent cannot revoke either, and addresses already granted stay in place until the knoc is fixed.
Steps to Resolve
Fill In the Missing Setting
- Open the knoc in the Knocknoc admin interface and go to its settings
- Enter the setting named in the error message, exactly as it is named on the device
- Save the knoc
Saving pushes the corrected configuration to the agent, and the next grant uses it. An existing grant that failed with this code can be re-granted from the admin interface once the knoc is saved.
Knocs Saved Before an Upgrade
A knoc can reach this state without anyone editing it. Sophos SFOS is the example: support for IPv6 grants added a second host group to the configuration, and knocs saved before that release carry only the IPv4 one. Their IPv4 grants keep working and their IPv6 grants report this code until the IPv6 host group is filled in.
The AWS region, Google Cloud project and Meraki organization are set on each knoc. An upgrade from a release that set them on the integration copies the integration's value onto each of its knocs, so only a knoc whose integration had no value reaches this state.
Confirm the Group Exists on the Device
Filling in a name that the device does not have moves the failure rather than fixing it: the agent reaches the device and the device rejects the change, which reports as a backend error for that vendor instead. Check the group name against the device before saving, and use Validate on the knoc where the backend supports it.