<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Test Case Security Features on FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/test-case-security-features-on-ftd/m-p/4285870#M1078112</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Download nping, put it in a machine in the outside zone and use the&lt;BR /&gt;following&lt;BR /&gt;&lt;BR /&gt;nping --tcp -p 80 -S 1.1.1.1 1.1.1.1  -- this is for case 1. It should be&lt;BR /&gt;blocked by rpf check&lt;BR /&gt;nping --tcp -p 139 1.1.1.1 -- this is for case 2&lt;BR /&gt;&lt;BR /&gt;If you enable terminate monitoring on ASA or send syslogs to external&lt;BR /&gt;server you can look for the messages.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
    <pubDate>Thu, 04 Feb 2021 07:36:53 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2021-02-04T07:36:53Z</dc:date>
    <item>
      <title>Test Case Security Features  on FTD</title>
      <link>https://community.cisco.com/t5/network-security/test-case-security-features-on-ftd/m-p/4285748#M1078108</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;Pls suggest me how to to do the following tests in FTD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Case 1)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test Item -&lt;/STRONG&gt;Detect Land Attack&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test procedure /Reference&lt;/STRONG&gt; - Same Source IP/port to destination IP/Port to be generated on the outside&amp;nbsp; interface&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Expected result -&lt;/STRONG&gt; Deny traffic should be shown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Case 2)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test Item -&lt;/STRONG&gt;Win Nuke attack&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test procedure /Reference&lt;/STRONG&gt; - traffic to tcp 139 port to be generated on outside interface&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Expected result -&lt;/STRONG&gt; Deny traffic should be shown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have selected the both options in intrusion policy but not get the idea how to demonstrate the condition and achieve the result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BB&lt;/P&gt;&lt;P&gt;Bibek&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 02:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/test-case-security-features-on-ftd/m-p/4285748#M1078108</guid>
      <dc:creator>bibek_deo</dc:creator>
      <dc:date>2021-02-04T02:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Test Case Security Features on FTD</title>
      <link>https://community.cisco.com/t5/network-security/test-case-security-features-on-ftd/m-p/4285870#M1078112</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Download nping, put it in a machine in the outside zone and use the&lt;BR /&gt;following&lt;BR /&gt;&lt;BR /&gt;nping --tcp -p 80 -S 1.1.1.1 1.1.1.1  -- this is for case 1. It should be&lt;BR /&gt;blocked by rpf check&lt;BR /&gt;nping --tcp -p 139 1.1.1.1 -- this is for case 2&lt;BR /&gt;&lt;BR /&gt;If you enable terminate monitoring on ASA or send syslogs to external&lt;BR /&gt;server you can look for the messages.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Thu, 04 Feb 2021 07:36:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/test-case-security-features-on-ftd/m-p/4285870#M1078112</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-02-04T07:36:53Z</dc:date>
    </item>
  </channel>
</rss>

