<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic There isn't one that I know in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3052217#M43049</link>
    <description>&lt;P&gt;There isn't one that I know of. However note if you are running the ASA image you can follow that. FTD is too new to have one out.&lt;/P&gt;
&lt;P&gt;Note there are some features introduced in FX-OS 2.1(1) that are specific to hardening. Among them are:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="pBu1_Bullet1"&gt;■&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="10" height="2" border="0" /&gt;&lt;/A&gt;You can now use the FXOS Chassis Manager to enable FIPs/Common Criteria mode to support achieving compliance with FIPS (Federal Information Processing Standard) 140-2 and Common Criteria security certifications.&lt;/P&gt;
&lt;P class="pBu1_Bullet1"&gt;&lt;A name="pgfId-143200"&gt;&lt;/A&gt;■&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="10" height="2" border="0" /&gt;&lt;/A&gt;FXOS 2.1(1) contains several new features and numerous enhancements to support achieving compliance with the UC-APL (Unified Capabilities Approved Product List) security certification:&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143201"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Enable/Disable FIPS/CC Mode using Firepower Chassis Manager&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143202"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Configuring Management ACL (ip-block) via Firepower Chassis Manager&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143203"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Configuring SSH Server – MAC Authentication via Firepower Chassis Manager&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143204"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Configuring SSH Server – Encryption Algorithms via Firepower Chassis Manager&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143205"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Login Notifications&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143206"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Periodic update of CRL list&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143207"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Client Cert authentication&lt;/P&gt;
&lt;P class="pBu1_Bullet1"&gt;&lt;A name="pgfId-143709"&gt;&lt;/A&gt;■&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="10" height="2" border="0" /&gt;&lt;/A&gt;You can now enable NTP server authentication.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos211/release/notes/fxos211_rn.html#pgfId-148118&lt;/P&gt;</description>
    <pubDate>Tue, 14 Mar 2017 13:50:55 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-03-14T13:50:55Z</dc:date>
    <item>
      <title>Official Hardening Guide for Firepower 4100 Series</title>
      <link>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3052216#M43047</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;Anyone know if there's a official hardening guide for Cisco Firepower 4100 series platform ?&lt;/P&gt;
&lt;P&gt;I only manage to find guide for ASA Firewall&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/200150-Cisco-Guide-to-Harden-Cisco-ASA-Firewall.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/200150-Cisco-Guide-to-Harden-Cisco-ASA-Firewall.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3052216#M43047</guid>
      <dc:creator>seekianherng</dc:creator>
      <dc:date>2019-03-10T13:47:46Z</dc:date>
    </item>
    <item>
      <title>There isn't one that I know</title>
      <link>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3052217#M43049</link>
      <description>&lt;P&gt;There isn't one that I know of. However note if you are running the ASA image you can follow that. FTD is too new to have one out.&lt;/P&gt;
&lt;P&gt;Note there are some features introduced in FX-OS 2.1(1) that are specific to hardening. Among them are:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="pBu1_Bullet1"&gt;■&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="10" height="2" border="0" /&gt;&lt;/A&gt;You can now use the FXOS Chassis Manager to enable FIPs/Common Criteria mode to support achieving compliance with FIPS (Federal Information Processing Standard) 140-2 and Common Criteria security certifications.&lt;/P&gt;
&lt;P class="pBu1_Bullet1"&gt;&lt;A name="pgfId-143200"&gt;&lt;/A&gt;■&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="10" height="2" border="0" /&gt;&lt;/A&gt;FXOS 2.1(1) contains several new features and numerous enhancements to support achieving compliance with the UC-APL (Unified Capabilities Approved Product List) security certification:&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143201"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Enable/Disable FIPS/CC Mode using Firepower Chassis Manager&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143202"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Configuring Management ACL (ip-block) via Firepower Chassis Manager&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143203"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Configuring SSH Server – MAC Authentication via Firepower Chassis Manager&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143204"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Configuring SSH Server – Encryption Algorithms via Firepower Chassis Manager&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143205"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Login Notifications&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143206"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Periodic update of CRL list&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;&lt;A name="pgfId-143207"&gt;&lt;/A&gt;–&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="19" height="2" border="0" /&gt;&lt;/A&gt;Client Cert authentication&lt;/P&gt;
&lt;P class="pBu1_Bullet1"&gt;&lt;A name="pgfId-143709"&gt;&lt;/A&gt;■&lt;A href="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" class="show-image-alone" title="Related image, diagram or screenshot."&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="10" height="2" border="0" /&gt;&lt;/A&gt;You can now enable NTP server authentication.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos211/release/notes/fxos211_rn.html#pgfId-148118&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 13:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3052217#M43049</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-14T13:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Official Hardening Guide for Firepower 4100 Series</title>
      <link>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3306344#M43053</link>
      <description>&lt;P&gt;I wrote something in my blog about the ICMP issues (&lt;A href="https://www.lammle.com/about/blog/" target="_blank"&gt;https://www.lammle.com/about/blog/&lt;/A&gt;) where I discuss how the FTD is NOT like the ASA...this basically describes the hardening problem and provides only the ICMP solution.&lt;/P&gt;
&lt;P&gt;I am working hard on writing a hardening chapter for my new FTD book..March 2018!&lt;/P&gt;
&lt;P&gt;This is desperately needed by ALL my customers!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Todd Lammle&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 20:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3306344#M43053</guid>
      <dc:creator>toddlammle</dc:creator>
      <dc:date>2018-01-04T20:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Official Hardening Guide for Firepower 4100 Series</title>
      <link>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3779971#M43056</link>
      <description>&lt;P&gt;Does anyone have&amp;nbsp;Cisco Firepower, FTD, FMC hardening guide.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 10:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3779971#M43056</guid>
      <dc:creator>John500</dc:creator>
      <dc:date>2019-01-15T10:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Official Hardening Guide for Firepower 4100 Series</title>
      <link>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3780152#M43058</link>
      <description>So I started discussing this a year or so ago with some of my staff, and the reality is the hardening for the FMC is System&amp;gt;Configuration, but the real hardening for the FTD is completely in the Device&amp;gt;Platform Settings.&lt;BR /&gt;&lt;BR /&gt;It wasn’t enough to write a book about, but it is very important, so I added the intense labs into my class and also did a video series on it at my web site.&lt;BR /&gt;&lt;BR /&gt;I can’t list the web site or they’d just delete it here, but its my name ☺&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;Todd Lammle&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 15 Jan 2019 14:33:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3780152#M43058</guid>
      <dc:creator>toddlammle</dc:creator>
      <dc:date>2019-01-15T14:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Official Hardening Guide for Firepower 4100 Series</title>
      <link>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3780314#M43060</link>
      <description>Hello Sir I am your big fun &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/12963"&gt;@tod&lt;/a&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/official-hardening-guide-for-firepower-4100-series/m-p/3780314#M43060</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-15T16:51:40Z</dc:date>
    </item>
  </channel>
</rss>

