<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: c2911 Firewalling and IDS/IPS for PCI DSS compliance in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3180001#M1041618</link>
    <description>You would need to buy a security licence for the routers and then you could implement zone based firewall.</description>
    <pubDate>Tue, 05 Sep 2017 09:52:42 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2017-09-05T09:52:42Z</dc:date>
    <item>
      <title>c2911 Firewalling and IDS/IPS for PCI DSS compliance</title>
      <link>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3179789#M1041614</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;One customer wants to be audited for PCI DSS compliance. They have c2911 routers as WAN routers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When they do port scanning, obviously there are some ports open as routers are doing natting. As far as I know, port scanning cannot be prevented with ACLs. We need some firewalling or/and IDS/IPS functionalities on the router to avoid it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone give me hand with this topic? Do I need to upgrade to a higher IOS version? any security licence?&amp;nbsp;&lt;/P&gt;&lt;P&gt;these are the version details of the routers&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.1(4)M4, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;Technology Package License Information for Module:'c2900'&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------&lt;BR /&gt;Technology Technology-package Technology-package&lt;BR /&gt;Current Type Next reboot&lt;BR /&gt;------------------------------------------------------------------&lt;BR /&gt;ipbase ipbasek9 Permanent ipbasek9&lt;BR /&gt;security None None None&lt;BR /&gt;uc None None None&lt;BR /&gt;data None None None&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3179789#M1041614</guid>
      <dc:creator>Enrique Roques Gomez</dc:creator>
      <dc:date>2020-02-21T14:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: c2911 Firewalling and IDS/IPS for PCI DSS compliance</title>
      <link>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3180001#M1041618</link>
      <description>You would need to buy a security licence for the routers and then you could implement zone based firewall.</description>
      <pubDate>Tue, 05 Sep 2017 09:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3180001#M1041618</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2017-09-05T09:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: c2911 Firewalling and IDS/IPS for PCI DSS compliance</title>
      <link>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3180081#M1041621</link>
      <description>&lt;P&gt;Hello Philip,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your quick response. Could we get a similar result regarding port scanning with reflexive ACL?&lt;/P&gt;&lt;P&gt;I know it is not as powerful as CBAC but we might prevent port scanning tools from seeing open ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 12:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3180081#M1041621</guid>
      <dc:creator>Enrique Roques Gomez</dc:creator>
      <dc:date>2017-09-05T12:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: c2911 Firewalling and IDS/IPS for PCI DSS compliance</title>
      <link>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3180271#M1041623</link>
      <description>&lt;P&gt;You can't get the same result using reflective ACLs because they leave the ports permanelty open.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CBAC and zone based firewall only leave the ports open while they need to be and then close them again.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 18:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2911-firewalling-and-ids-ips-for-pci-dss-compliance/m-p/3180271#M1041623</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2017-09-05T18:39:08Z</dc:date>
    </item>
  </channel>
</rss>

