<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firesight Nmap active scan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770444#M1038199</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to enable Nmap instance in Firesight 5.4.1 and a bit confused with the following two points:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I noticed in&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Scanning.html#pgfId-3355672" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Scanning.html#pgfId-3355672&lt;/A&gt; it states &amp;nbsp;'Step 6 Optionally, to run the scan from a remote device instead of the Defense Center, specify the IP address or name of the device as it appears in the Information page for the device in the Defense Center web interface, in the Remote Device Name field.', does it mean that if I provide the IP of a Firepower module (we have three SFR modules deployed in three branch offices and the Defense Center in HQ) the active scanner will be enabled there and the scan will be launched from the firepower module?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Can Firesight 5.4.1 run a credentialed active scan? I don't see where I can provide domain level privileges for Firesight to run such a scan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 12:47:36 GMT</pubDate>
    <dc:creator>Meng Li</dc:creator>
    <dc:date>2019-03-12T12:47:36Z</dc:date>
    <item>
      <title>Firesight Nmap active scan</title>
      <link>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770444#M1038199</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to enable Nmap instance in Firesight 5.4.1 and a bit confused with the following two points:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I noticed in&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Scanning.html#pgfId-3355672" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Scanning.html#pgfId-3355672&lt;/A&gt; it states &amp;nbsp;'Step 6 Optionally, to run the scan from a remote device instead of the Defense Center, specify the IP address or name of the device as it appears in the Information page for the device in the Defense Center web interface, in the Remote Device Name field.', does it mean that if I provide the IP of a Firepower module (we have three SFR modules deployed in three branch offices and the Defense Center in HQ) the active scanner will be enabled there and the scan will be launched from the firepower module?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Can Firesight 5.4.1 run a credentialed active scan? I don't see where I can provide domain level privileges for Firesight to run such a scan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770444#M1038199</guid>
      <dc:creator>Meng Li</dc:creator>
      <dc:date>2019-03-12T12:47:36Z</dc:date>
    </item>
    <item>
      <title>Any thoughts on this? Thanks,</title>
      <link>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770445#M1038204</link>
      <description>&lt;P&gt;Any thoughts on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 04:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770445#M1038204</guid>
      <dc:creator>Meng Li</dc:creator>
      <dc:date>2015-10-27T04:18:33Z</dc:date>
    </item>
    <item>
      <title>The short answer to #1 is yes</title>
      <link>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770446#M1038212</link>
      <description>&lt;P&gt;The short answer to #1 is yes. &amp;nbsp;When you setup an nmap scan if you enter the remote device IP address the scan will kick off and run from the SFR module. &amp;nbsp;The scan will be performed&amp;nbsp;through the management interface.&lt;/P&gt;
&lt;P&gt;As for #2 I don't believe nmap has a credentialed scan capability and nmap is what we use for the scanner.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 16:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770446#M1038212</guid>
      <dc:creator>atatistc</dc:creator>
      <dc:date>2015-10-30T16:43:01Z</dc:date>
    </item>
    <item>
      <title>Thanks for the information! </title>
      <link>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770447#M1038217</link>
      <description>&lt;P&gt;Thanks for the information!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm running a scan to a remote site via a quite congested WAN link, and it's still running. Is there a way to stop the scan job in the Mgmt GUI?&lt;/P&gt;
&lt;P&gt;Also in the firesight, is it possible to run more than one scan at the same tmie?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2015 21:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770447#M1038217</guid>
      <dc:creator>Meng Li</dc:creator>
      <dc:date>2015-11-02T21:13:43Z</dc:date>
    </item>
    <item>
      <title>I stopped like this</title>
      <link>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770448#M1038226</link>
      <description>&lt;P&gt;I stopped like this&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;go on the CLI of the machine running the scan&lt;/P&gt;
&lt;P&gt;enter expert mode&lt;BR /&gt;then, type sudo su -&lt;BR /&gt;put the password&lt;BR /&gt;type ps -ef | grep nmap&lt;/P&gt;
&lt;P&gt;Find the process ID&lt;/P&gt;
&lt;P&gt;then&lt;/P&gt;
&lt;P&gt;kill -9 PID&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Example&lt;/P&gt;
&lt;P&gt;root@firepower:~# ps -ef | grep nmap&lt;BR /&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 898&amp;nbsp;&amp;nbsp; 847&amp;nbsp; 3 01:41 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:41:48 /usr/local/sf/nmap/bin/nmap&lt;/P&gt;
&lt;P&gt;root@firepower:~# kill -9 898&lt;/P&gt;
&lt;P&gt;That's it...&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 00:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-nmap-active-scan/m-p/2770448#M1038226</guid>
      <dc:creator>wbarboza</dc:creator>
      <dc:date>2017-06-28T00:03:27Z</dc:date>
    </item>
  </channel>
</rss>

