<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA default configuration - Threat Detection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3212165#M1023069</link>
    <description>&lt;P&gt;Good day,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We provide data services to different customers. Our frontier to the Internet is an ASA 5510 running version 8.2(5). Security related, we have the default configuration with some ACLs applied. We have a DMZ area configured as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this configuration enough? Or is there any functionality you recommend activating?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have basic threat detection enabled (default), and are considering changing it to advanced threat detection or even scanning threat detection. However, we don't know what parameters to check to see whether this may have an impact on our system (traffic is not too much so we don't think it should be an issue). Would you recommend going for advanced or scanning threat detection? what parameters should we check first?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do not want to limit our client's traffic, but we do want to have our network protected from external threats and attacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you all in advance.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Marta&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 14:39:49 GMT</pubDate>
    <dc:creator>marta.mendez</dc:creator>
    <dc:date>2020-02-21T14:39:49Z</dc:date>
    <item>
      <title>ASA default configuration - Threat Detection</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3212165#M1023069</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We provide data services to different customers. Our frontier to the Internet is an ASA 5510 running version 8.2(5). Security related, we have the default configuration with some ACLs applied. We have a DMZ area configured as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this configuration enough? Or is there any functionality you recommend activating?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have basic threat detection enabled (default), and are considering changing it to advanced threat detection or even scanning threat detection. However, we don't know what parameters to check to see whether this may have an impact on our system (traffic is not too much so we don't think it should be an issue). Would you recommend going for advanced or scanning threat detection? what parameters should we check first?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do not want to limit our client's traffic, but we do want to have our network protected from external threats and attacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you all in advance.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Marta&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3212165#M1023069</guid>
      <dc:creator>marta.mendez</dc:creator>
      <dc:date>2020-02-21T14:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default configuration - Threat Detection</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3212565#M1023070</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;A id="link_14" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/445134" target="_self"&gt;marta.mendez&lt;/A&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Good day.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;First of all, I would like to bring it to your notice that 8.2(5 ) is a very old version. You must upgrade your device to some stable 9.2.(x ) version. If you need help in that please let me know.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Secondly, You can also make use of Nat'ing functionalities, if required.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;If you have dual ISP connection for fault tolerance, you must use SLA-monitor feature.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Coming to threat detection feature, obviously you can use advanced and scanning threat detection feature. It does take a toll on CPU but as you say that you dont have much traffic flowing across, you can go for it. Always keep in mind, "threat detection" just detects the possibility of threat and alert us but does not prevent.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-New-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;For more granularity on the subject, you can refer to the link below: -&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please do select and rate the correct answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Dubey, Shivam&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 19:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3212565#M1023070</guid>
      <dc:creator>er.shivamdubey31190</dc:creator>
      <dc:date>2017-11-07T19:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default configuration - Threat Detection</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3213086#M1023071</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/266979"&gt;@er.shivamdubey31190&lt;/a&gt;!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for upgrading the device to 9.2.(x), we didn't get a contract service for the ASA. It's now end of life, and we haven't found a way to get a maintenance for it to have access to IOS downloads.&lt;/P&gt;
&lt;P&gt;Do you know how we can activate this device in Cisco to be able to upgrade the IOS?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are going to activate advanced threat detection on the ASA. Even though it does not prevent, we would like to have the logs to know if we are under attack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Marta&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 12:38:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3213086#M1023071</guid>
      <dc:creator>marta.mendez</dc:creator>
      <dc:date>2017-11-08T12:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default configuration - Threat Detection</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3306177#M1023072</link>
      <description>&lt;P&gt;Dear Marta,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am sorry, I could not revert back to you on time as I was unwell.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wishing you a very happy new year.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Coming to the contract related concern, Please help me with the ASA model.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even if the ASA is end of life, you can request for the Asa OS download.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a valid cisco support contract, if yes, you can for raise a TAC case and ask for the support.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Shivam &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 16:19:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-configuration-threat-detection/m-p/3306177#M1023072</guid>
      <dc:creator>er.shivamdubey31190</dc:creator>
      <dc:date>2018-01-04T16:19:55Z</dc:date>
    </item>
  </channel>
</rss>

