<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA IP Audit in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068037#M1069278</link>
    <description>&lt;P&gt;I've never seen the feature used in production in the past decade of working with 100s of ASA firewalls.&lt;/P&gt;
&lt;P&gt;If you have a current ASA with Firepower service module, the basic IPS policy enforced by the service module (most often "Balanced Security and Connectivity") would the the analogous feature. It would also more closely reflect what's appropriate for the current threat landscape.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2020 11:13:53 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2020-04-17T11:13:53Z</dc:date>
    <item>
      <title>ASA IP Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4067253#M1069241</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've got a new ASA Firepower which replaces an other old ASA. The old one has various IP Audit Policies configured, but I think for legacy reasons.&lt;/P&gt;
&lt;P&gt;What is the default today in regards to IP Audit?&lt;/P&gt;
&lt;P&gt;Is this enabled by default or not?&lt;/P&gt;
&lt;P&gt;What are your recommendations?&lt;/P&gt;
&lt;P&gt;I could only find this in the legacy documentation for ASA 9.12.x image, so I assume it should be left disabled, unless there are good reasons to enable it?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/legacy/asa-legacy-gd/protect-tools.html#26683" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/legacy/asa-legacy-gd/protect-tools.html#26683&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This device terminates exclusively SSL VPN Client connections, if that is of importance, and sits behind another Firepower ASA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 14:36:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4067253#M1069241</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2020-04-16T14:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IP Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068037#M1069278</link>
      <description>&lt;P&gt;I've never seen the feature used in production in the past decade of working with 100s of ASA firewalls.&lt;/P&gt;
&lt;P&gt;If you have a current ASA with Firepower service module, the basic IPS policy enforced by the service module (most often "Balanced Security and Connectivity") would the the analogous feature. It would also more closely reflect what's appropriate for the current threat landscape.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 11:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068037#M1069278</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-17T11:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IP Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068054#M1069279</link>
      <description>I don't have a Firepower service module, "only" a Firepower 4110 running the pure ASA image. So no special IPS functionality licensed or similar.&lt;BR /&gt;&lt;BR /&gt;I guess it's slowly getting time to disable that feature, it was dragged from hardware to hardware &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Apr 2020 11:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068054#M1069279</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2020-04-17T11:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IP Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068061#M1069280</link>
      <description>&lt;P&gt;Ah OK. Hopefully the upstream ASA has the Firepower protections in place.&lt;/P&gt;
&lt;P&gt;I imagine the config was on an old Pix that might have been installed there once. That's the last place I recall seeing that config item used.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 12:00:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068061#M1069280</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-17T12:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IP Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068080#M1069282</link>
      <description>Nope no FTD image in use anywhere, just good old plain ASA, but with a ton of restrictions.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Apr 2020 12:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ip-audit/m-p/4068080#M1069282</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2020-04-17T12:31:07Z</dc:date>
    </item>
  </channel>
</rss>

