<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA threat-detection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711486#M190623</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to understand ASA threat-detection feature but I have not been able to find much details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I see&amp;nbsp;what criteria is used by ASA to determine if a connection is threat? Any documentation detailing this !&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:06:44 GMT</pubDate>
    <dc:creator>S891</dc:creator>
    <dc:date>2019-03-12T06:06:44Z</dc:date>
    <item>
      <title>ASA threat-detection</title>
      <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711486#M190623</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to understand ASA threat-detection feature but I have not been able to find much details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I see&amp;nbsp;what criteria is used by ASA to determine if a connection is threat? Any documentation detailing this !&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711486#M190623</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2019-03-12T06:06:44Z</dc:date>
    </item>
    <item>
      <title>hi try this commandsh run all</title>
      <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711487#M190624</link>
      <description>&lt;P&gt;hi try this command&lt;/P&gt;&lt;P&gt;sh run all threat detection&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2015 19:21:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711487#M190624</guid>
      <dc:creator>Ahmad Khalifa</dc:creator>
      <dc:date>2015-06-15T19:21:34Z</dc:date>
    </item>
    <item>
      <title>Hi,Actually , the drops on</title>
      <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711488#M190625</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Actually , the drops on which the ASA Threat detection works is the "show asp drop".&lt;/P&gt;&lt;P&gt;Based on these drops rate , it matches the default parameter and uses the threat detection to possibility block hosts.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2015 13:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711488#M190625</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-16T13:32:34Z</dc:date>
    </item>
    <item>
      <title>Hi ,Can you please clarify</title>
      <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711489#M190626</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Can you please clarify the criteria threat-detection uses to detect if it is a threat? For example, if it sees an IP address trying to connect to X number of hosts and makes Y number of attempts then it is considered a threat.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In short, how would I determine if a particular connection attempt may be considered a threat.&lt;/P&gt;&lt;P&gt;I have seen some legitimate connections attempts were considered as threat and the IP was shunned.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2015 07:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711489#M190626</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2015-06-19T07:18:06Z</dc:date>
    </item>
    <item>
      <title>Hi,To explain this , ASA</title>
      <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711490#M190627</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;To explain this , ASA device has a static value of each of these drops rate and it would remain the same in different networks some which has large amount of traffic and others not that much.&lt;/P&gt;&lt;P&gt;The rate might be high for some addresses but that can be legitimate.&lt;/P&gt;&lt;P&gt;I think to get rid of this , there would be two ways:-&lt;/P&gt;&lt;P&gt;1) use the Except command for the addresses which should never be blocked&lt;/P&gt;&lt;P&gt;Refer:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/T-Z/cmdref4/t1.html#pgfId-1563523&lt;/P&gt;&lt;P&gt;2) Run this command , show run all threat-detection and modify the rates as per your requirement which are seen the most in the logs.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2015 11:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711490#M190627</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-19T11:20:31Z</dc:date>
    </item>
    <item>
      <title>thanks Vibhor. Can you give</title>
      <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711491#M190628</link>
      <description>&lt;P&gt;thanks Vibhor. Can you give an example for this? For example, how the below rate- interval would work and when would it block an IP in this case?&lt;/P&gt;&lt;P&gt;&lt;B class="cBold" style="color: rgb(0, 0, 0); font-family: 'Courier New', Courier, mono; font-size: 12.8800001144409px; line-height: 18px;"&gt;threat-detection rate scanning-threat rate-interval 500 average-rate 10 burst-rate 20&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2015 11:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711491#M190628</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2015-06-19T11:41:12Z</dc:date>
    </item>
    <item>
      <title>hii think you can not go</title>
      <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711492#M190629</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;i think you can not go below 600&amp;nbsp;rate-interval&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2015 22:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711492#M190629</guid>
      <dc:creator>Ahmad Khalifa</dc:creator>
      <dc:date>2015-06-22T22:14:08Z</dc:date>
    </item>
    <item>
      <title>Hi,These values can only be</title>
      <link>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711493#M190630</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;These values can only be specified within a range and has to be set on a trial and error basis as the the network activity.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2015 11:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-threat-detection/m-p/2711493#M190630</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-23T11:45:05Z</dc:date>
    </item>
  </channel>
</rss>

