<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASDM vulnerability concern in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693697#M1009801</link>
    <description>&lt;P&gt;Hello;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm contimplating on using ASDM as a tool to monitor my PIX 525 in terms of VPN trhoughput, interface stats and perform the security check, all of which the asdm program offers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I prefer to use the CLI to implement change, and I will continue this practive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is "Should I be concerned if I enable http inside 192.168.1.0 255.255.255.0 so that I can access the installed asdm application?" Are there any security concerns? I'm thinking as long as I specify the host that will be used to access the PIX, I should be okay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your feedback is apreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:49:28 GMT</pubDate>
    <dc:creator>jkrawczyk</dc:creator>
    <dc:date>2019-03-11T09:49:28Z</dc:date>
    <item>
      <title>ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693697#M1009801</link>
      <description>&lt;P&gt;Hello;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm contimplating on using ASDM as a tool to monitor my PIX 525 in terms of VPN trhoughput, interface stats and perform the security check, all of which the asdm program offers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I prefer to use the CLI to implement change, and I will continue this practive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is "Should I be concerned if I enable http inside 192.168.1.0 255.255.255.0 so that I can access the installed asdm application?" Are there any security concerns? I'm thinking as long as I specify the host that will be used to access the PIX, I should be okay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your feedback is apreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:49:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693697#M1009801</guid>
      <dc:creator>jkrawczyk</dc:creator>
      <dc:date>2019-03-11T09:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693698#M1009803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;rather than making it for the entire subnet why dont you make it specific to few hosts..till the time you have your enable credentials safe..you are safe as well..:-)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 17:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693698#M1009803</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-20T17:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693699#M1009804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, yes good idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I'm thinking will asdm use my tacacs service. If not, I need to find out how to configure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 17:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693699#M1009804</guid>
      <dc:creator>jkrawczyk</dc:creator>
      <dc:date>2007-03-20T17:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693700#M1009805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you mean you have a TACACS Server configured ?..if yes then  you can get ASDM authenticated via TACACS as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 17:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693700#M1009805</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-20T17:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693701#M1009806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I currently use tacacs server. Changed config is below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to fond out if this config will use tacacs without any additional commands. I would think I would need to specify the authentication such as https.  still digging on this issue. Thanks for the feedback,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server ABCACS protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server ABCACS host 192.168.100.1&lt;/P&gt;&lt;P&gt; key guessme&lt;/P&gt;&lt;P&gt;aaa authentication ssh console ABCACS &lt;/P&gt;&lt;P&gt;aaa authentication enable console ABCACS &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 17:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693701#M1009806</guid>
      <dc:creator>jkrawczyk</dc:creator>
      <dc:date>2007-03-20T17:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693702#M1009807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;add one more command for ASDM auth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication http console ABACS &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case you are not using the fall back mechanism that means if TACACS server is down ..then you would be completely locked&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 18:16:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693702#M1009807</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-20T18:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693703#M1009809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently if tacacs is down, my local account can be accessed via ssh or console by using the default ?pix? local account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you saying if I include ?aaa authentication http console ABCACS?, I will not be able ssh into my PIX not even bby using the local ?pix? account? I?m a little confused. All configuration changes will be made from either my console or ssh session. ASDM will be used only for monitoring, but I want to authenticate with my tacacs server when I access my PIX via http as well as ssh and console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 19:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693703#M1009809</guid>
      <dc:creator>jkrawczyk</dc:creator>
      <dc:date>2007-03-20T19:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693704#M1009812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes you dont have a fallback configured that means that if your TACACS server is unreachable then you would not be able to access the firewall using ssh or console&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to configure fallback to the local database try this :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console ABACS local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 22:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693704#M1009812</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-20T22:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM vulnerability concern</title>
      <link>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693705#M1009816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hope this helps &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/cmd_ref/a1_711.htm#wp1437931" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/cmd_ref/a1_711.htm#wp1437931&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 22:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-vulnerability-concern/m-p/693705#M1009816</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-20T22:49:43Z</dc:date>
    </item>
  </channel>
</rss>

