<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Implementation problems with Botnet on ASA-Context FW in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/implementation-problems-with-botnet-on-asa-context-fw/m-p/2547344#M237170</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm currently trying to implement a trial Botnet Traffic Filter on a ASA5520 multicontext.&lt;/P&gt;&lt;P&gt;It's running in a data center, with ~10 customer contexts. When I tried to enable it, we had a bunch of dropped pings on different contexts. I'm not really sure if there is anything wrong in the configuration, or if this is some kind of bug, or even normal behavior.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Licence is activated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin-context:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;dns domain-lookup outside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;name-server 8.8.8.8&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;system-context:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;dynamic-filter updater-client enable&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;customer-context:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;dynamic-filter use-database&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;access-list dynamic-filter_acl extended permit ip 10.140.1.0 255.255.255.0 any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;dynamic-filter enable interface outside classify-list dynamic-filter_acl&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;policy-map global_policy&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns dynamic-filter-snoop&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After implementing the commands on the system/admin context, the pings to google.com started to drop (4 drops, 6 ok, 3 drops, 10 ok, 1 drop, 1 ok,...).&lt;/P&gt;&lt;P&gt;Has anyone an idea how we can get this runnning without impact on our customers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Amir&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:23:12 GMT</pubDate>
    <dc:creator>amir.glibic</dc:creator>
    <dc:date>2019-03-12T04:23:12Z</dc:date>
    <item>
      <title>Implementation problems with Botnet on ASA-Context FW</title>
      <link>https://community.cisco.com/t5/network-security/implementation-problems-with-botnet-on-asa-context-fw/m-p/2547344#M237170</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm currently trying to implement a trial Botnet Traffic Filter on a ASA5520 multicontext.&lt;/P&gt;&lt;P&gt;It's running in a data center, with ~10 customer contexts. When I tried to enable it, we had a bunch of dropped pings on different contexts. I'm not really sure if there is anything wrong in the configuration, or if this is some kind of bug, or even normal behavior.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Licence is activated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin-context:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;dns domain-lookup outside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;name-server 8.8.8.8&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;system-context:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;dynamic-filter updater-client enable&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;customer-context:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;dynamic-filter use-database&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;access-list dynamic-filter_acl extended permit ip 10.140.1.0 255.255.255.0 any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;dynamic-filter enable interface outside classify-list dynamic-filter_acl&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;policy-map global_policy&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&lt;EM&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns dynamic-filter-snoop&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After implementing the commands on the system/admin context, the pings to google.com started to drop (4 drops, 6 ok, 3 drops, 10 ok, 1 drop, 1 ok,...).&lt;/P&gt;&lt;P&gt;Has anyone an idea how we can get this runnning without impact on our customers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Amir&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/implementation-problems-with-botnet-on-asa-context-fw/m-p/2547344#M237170</guid>
      <dc:creator>amir.glibic</dc:creator>
      <dc:date>2019-03-12T04:23:12Z</dc:date>
    </item>
    <item>
      <title>Hi Amir, Its advised to use</title>
      <link>https://community.cisco.com/t5/network-security/implementation-problems-with-botnet-on-asa-context-fw/m-p/2547345#M237171</link>
      <description>&lt;P&gt;Hi Amir,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its advised to use the local dns or your isp provided dns.... that also could be the reason... also you are filtering for one subnet which should not affect the other context or users.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 10:21:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/implementation-problems-with-botnet-on-asa-context-fw/m-p/2547345#M237171</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-06-26T10:21:11Z</dc:date>
    </item>
  </channel>
</rss>

