<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD PoC Customer concerns in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-poc-customer-concerns/m-p/3808215#M17951</link>
    <description>&lt;P&gt;I have some questions from my customer, Could you help on it? I wrote some responses but I need to check if there is more accurate responses&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We did the PoC by FTD2110 v6.2.3&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1- if 2 user edit the config then deploy done by one the second admin still see the old config however refresh , reload done only new config appeared after log out and re log in.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt; I tried to do that in my Lab and found that when some one changed the config it appears to the other, but as Cisco SE told me that the FMC doesn’t support Multi-Admin login.&lt;/P&gt;
&lt;P&gt;So any one faced that before and how to fix that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt; &lt;STRONG&gt;He receives the logs in SIEM with UTC time while he saw these logs on FMC in the actual time.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When We investigated that we found the following link which mentioned that CLI uses UTC and it is not recommended to change it, So is there is any other solution for that?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/firepower/ftd-2100-ntp-timezone-issue/td-p/3371929" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/firepower/ftd-2100-ntp-timezone-issue/td-p/3371929&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3- Full nessus scan passed through FTD but we received poor information unlike Paloalto as FTD didn’t log the Client used by scanner plugins&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I think this can be done because of Base IPS signature applied, or you can advice something else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;4-Decryption has been applied successfully but not working on time it took around 15 minutes to receive logs has been decrypted .&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The PoC done on FTD2110 version 6.2.3 while the real implementation will be FTD4110 version 6.3 which will use HW Decryption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;5-we couldn’t configure time based security policy . I think it’s not supported&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Time based Security policy is not supported yet, but it can be simulated with Paython script like below link.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-blogs/time-based-acls-in-firepower-threat-defense-ftd-v6-2/ba-p/3664122" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-blogs/time-based-acls-in-firepower-threat-defense-ftd-v6-2/ba-p/3664122&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Best regards,&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:51:18 GMT</pubDate>
    <dc:creator>Mzamzam</dc:creator>
    <dc:date>2020-02-21T16:51:18Z</dc:date>
    <item>
      <title>FTD PoC Customer concerns</title>
      <link>https://community.cisco.com/t5/network-security/ftd-poc-customer-concerns/m-p/3808215#M17951</link>
      <description>&lt;P&gt;I have some questions from my customer, Could you help on it? I wrote some responses but I need to check if there is more accurate responses&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We did the PoC by FTD2110 v6.2.3&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1- if 2 user edit the config then deploy done by one the second admin still see the old config however refresh , reload done only new config appeared after log out and re log in.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt; I tried to do that in my Lab and found that when some one changed the config it appears to the other, but as Cisco SE told me that the FMC doesn’t support Multi-Admin login.&lt;/P&gt;
&lt;P&gt;So any one faced that before and how to fix that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt; &lt;STRONG&gt;He receives the logs in SIEM with UTC time while he saw these logs on FMC in the actual time.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When We investigated that we found the following link which mentioned that CLI uses UTC and it is not recommended to change it, So is there is any other solution for that?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/firepower/ftd-2100-ntp-timezone-issue/td-p/3371929" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/firepower/ftd-2100-ntp-timezone-issue/td-p/3371929&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3- Full nessus scan passed through FTD but we received poor information unlike Paloalto as FTD didn’t log the Client used by scanner plugins&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I think this can be done because of Base IPS signature applied, or you can advice something else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;4-Decryption has been applied successfully but not working on time it took around 15 minutes to receive logs has been decrypted .&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The PoC done on FTD2110 version 6.2.3 while the real implementation will be FTD4110 version 6.3 which will use HW Decryption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;5-we couldn’t configure time based security policy . I think it’s not supported&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;My Response&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Time based Security policy is not supported yet, but it can be simulated with Paython script like below link.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-blogs/time-based-acls-in-firepower-threat-defense-ftd-v6-2/ba-p/3664122" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-blogs/time-based-acls-in-firepower-threat-defense-ftd-v6-2/ba-p/3664122&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Best regards,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-poc-customer-concerns/m-p/3808215#M17951</guid>
      <dc:creator>Mzamzam</dc:creator>
      <dc:date>2020-02-21T16:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: FTD PoC Customer concerns</title>
      <link>https://community.cisco.com/t5/network-security/ftd-poc-customer-concerns/m-p/3808700#M17964</link>
      <description>HI Mzamzam, see answers bellow.

1. Answer: Only one person at a time can make the change and save. What might happen is to display a message stating that there is an updated version of the configuration. Because the administration is done through the form, it will only be changed after sending the information, you can not control this.

2. Since you will use the FMC, you can change the UTC to your location only in the FMC and from it, send the information to the SIEM. In this way, SIEM will present local time.

3. Right.

4. Right

5. Right.

Hope this helps.

Sign up for our channel to receive information and a few tutorials on Cisco security solutions.

&lt;A href="https://www.youtube.com/channel/UC6KHImW6F7Hz1k2-AY0n_oQ" target="_blank"&gt;https://www.youtube.com/channel/UC6KHImW6F7Hz1k2-AY0n_oQ&lt;/A&gt;</description>
      <pubDate>Mon, 25 Feb 2019 00:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-poc-customer-concerns/m-p/3808700#M17964</guid>
      <dc:creator>Alessandro Roberto Alves</dc:creator>
      <dc:date>2019-02-25T00:34:47Z</dc:date>
    </item>
  </channel>
</rss>

