<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Botnet Filter in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311737#M311668</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a document that should get you started:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/white_paper_c11-532091.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/white_paper_c11-532091.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there are more questions after going through that doc, fell free to ask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Oct 2013 14:29:01 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2013-10-02T14:29:01Z</dc:date>
    <item>
      <title>ASA Botnet Filter</title>
      <link>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311736#M311667</link>
      <description>&lt;P&gt;I have recently added the Botnet filter license to an ASA5510.&amp;nbsp; Im needing assistance with viewing the config and being able to know that it is working.&amp;nbsp; How can i test?&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311736#M311667</guid>
      <dc:creator>kdietz</dc:creator>
      <dc:date>2019-03-12T02:46:09Z</dc:date>
    </item>
    <item>
      <title>ASA Botnet Filter</title>
      <link>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311737#M311668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a document that should get you started:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/white_paper_c11-532091.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/white_paper_c11-532091.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there are more questions after going through that doc, fell free to ask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 14:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311737#M311668</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-10-02T14:29:01Z</dc:date>
    </item>
    <item>
      <title>ASA Botnet Filter</title>
      <link>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311738#M311669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's some show commands as per my FIREWALL notes and a useful link that i've bookmarked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;usually the ASA will generate a syslog if a bad or infected machine is detected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-8782"&gt;https://supportforums.cisco.com/docs/DOC-8782&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Commands to Verify Botnet Traffic Filtering Operation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Function&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Command Syntax&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dynamic database status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ciscoasa# show dynamic-filter updater-client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connections filtered&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ciscoasa# show dynamic-filter statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;List infected hosts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ciscoasa# show dynamic-filterreport infected-hosts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Top-n botnet activity&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ciscoasa# show dynamic-filter top [infected-hosts | malware-ports | malware-sites]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 03:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311738#M311669</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2013-10-03T03:53:10Z</dc:date>
    </item>
    <item>
      <title>ASA Botnet Filter</title>
      <link>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311739#M311670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to enable botnet filter as well for one of our customer. So is it possible to enable botnet filter in monitoring mode only, means without dropping any traffic or impacting the production environment ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Oct 2013 12:40:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311739#M311670</guid>
      <dc:creator>rmujeeb81</dc:creator>
      <dc:date>2013-10-04T12:40:45Z</dc:date>
    </item>
    <item>
      <title>ASA Botnet Filter</title>
      <link>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311740#M311671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the answer is no. the ASA will intercept DNS queries and match it against the configured blacklist sites on its database and drops the traffic. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2013 04:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311740#M311671</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2013-10-08T04:15:49Z</dc:date>
    </item>
    <item>
      <title>ASA Botnet Filter</title>
      <link>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311741#M311673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My filter was origanly set to monitor mode which wasnt dropping the malicous requests - Scenerio;&amp;nbsp; I have a DNS server where the filter is detecting as a malicouis host naking DNS requests.&amp;nbsp; My question is,&amp;nbsp; does this necessarily imply that the DNS server is infected or is it another host on my network using this DNS server for name resolution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 17:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-botnet-filter/m-p/2311741#M311673</guid>
      <dc:creator>kdietz</dc:creator>
      <dc:date>2013-10-11T17:38:07Z</dc:date>
    </item>
  </channel>
</rss>

