<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Prasoon, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978100#M43318</link>
    <description>&lt;P&gt;Hi Prasoon,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the reply. I do not have any CVE ID, but we did vulnerability scanning through rapid 7 nexpose. vulnerability report say that RFC 1323 timestamp.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Dec 2016 05:53:21 GMT</pubDate>
    <dc:creator>maruthu777</dc:creator>
    <dc:date>2016-12-22T05:53:21Z</dc:date>
    <item>
      <title>TCP Time stamp Vulnerability issue</title>
      <link>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978098#M43309</link>
      <description>&lt;P&gt;Hello Everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am using Huawei firewall and windows server 2012 R2 operating system in our environment, When we do vulnerability scanning through Nexpose scanner, It shows TCP time stamp vulnerability. When i try to disable in OS level, But cannot. Also Hauwei firewall also cannot solve TCP Timestamp Vulnerability.&amp;nbsp;So we wish to change firewall to CISCO ASA 5525X.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Before changing, Whether CISCO firewall can solve TCP timestamp issue?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Maruthu&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978098#M43309</guid>
      <dc:creator>maruthu777</dc:creator>
      <dc:date>2019-03-10T13:44:16Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978099#M43312</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Do you have any vulnerability CVE ID? It will be very difficult to predict a solution with this info. &lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="con-NoMargin hist-break-word prettyprint" style="font-family: monospace; line-height: 13px; white-space: pre-wrap; word-wrap: break-word; border: 0px; padding: 2px; margin: 0px; font-weight: normal; word-break: break-word; color: #222222; font-size: 13px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;&lt;SPAN style="font-size: 12pt; font-family: arial,helvetica,sans-serif;"&gt;Although, for the RFC 1323 Timestamp leak, you can disable the timestamps.
You will find the instructions below.

Cisco ASA 5500 Series Configuration Guide using the CLI, 8.2
 &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/conns_tcpnorm.html" title="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/conns_tcpnorm.html" target="_blank" style="color: #333435;"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/conns_tcpnorm.html&lt;/A&gt;

Remote service implements TCP timestamps
 &lt;A href="https://supportforums.cisco.com/discussion/11015136/remote-service-implements-tcp-timestamps" title="https://supportforums.cisco.com/discussion/11015136/remote-service-implements-tcp-timestamps" target="_blank" style="color: #015ba7; text-decoration: underline;"&gt;https://supportforums.cisco.com/discussion/11015136/remote-service-implements-tcp-timestamps&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 22 Dec 2016 04:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978099#M43312</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2016-12-22T04:49:15Z</dc:date>
    </item>
    <item>
      <title>Hi Prasoon,</title>
      <link>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978100#M43318</link>
      <description>&lt;P&gt;Hi Prasoon,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the reply. I do not have any CVE ID, but we did vulnerability scanning through rapid 7 nexpose. vulnerability report say that RFC 1323 timestamp.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 05:53:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978100#M43318</guid>
      <dc:creator>maruthu777</dc:creator>
      <dc:date>2016-12-22T05:53:21Z</dc:date>
    </item>
    <item>
      <title>Well that's very generic. I</title>
      <link>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978101#M43323</link>
      <description>&lt;P&gt;Well that's very generic. I guess above two links should help you.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 06:48:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978101#M43323</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2016-12-22T06:48:51Z</dc:date>
    </item>
    <item>
      <title>Please check if you add the</title>
      <link>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978102#M43327</link>
      <description>&lt;P&gt;Please check if you add the Tcp1323Opts registry key as follows:&lt;/P&gt;
&lt;H5 style="margin: 4pt 0cm 3pt;"&gt;&lt;EM&gt;&lt;SPAN lang="EN-US"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Arial;"&gt;Tcp1323Opts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/H5&gt;
&lt;P style="margin: 0cm 0cm 6pt;"&gt;&lt;SPAN style="font-family: Arial;"&gt;&lt;SPAN style="font-size: x-small;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;Key:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN-US"&gt; Tcpip\Parameters&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 6pt;"&gt;&lt;SPAN style="font-family: Arial;"&gt;&lt;SPAN style="font-size: x-small;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;Value Type:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN-US"&gt; REG_DWORD—number (flags)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 6pt;"&gt;&lt;SPAN style="font-family: Arial;"&gt;&lt;SPAN style="font-size: x-small;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;Valid Range:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN-US"&gt; 0 or 2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0cm -18pt 6pt 0cm;"&gt;&lt;SPAN lang="EN-US"&gt;&lt;SPAN style="font-family: Lucida Console;"&gt;&lt;SPAN style="font-size: x-small;"&gt;0 (disable the use of the TCP timestamps option)&lt;BR /&gt; 2 (enable the use of the TCP timestamps option)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0cm -18pt 6pt 0cm;"&gt;&lt;SPAN lang="EN-US"&gt;&lt;BR /&gt; &lt;SPAN style="font-family: Lucida Console;"&gt;&lt;SPAN style="font-size: x-small;"&gt;&lt;STRONG&gt;Default:&lt;/STRONG&gt; No value. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 6pt;"&gt;&lt;SPAN style="font-size: x-small;"&gt;&lt;SPAN style="font-family: Arial;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;Description: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN-US"&gt;This value controls the use of the RFC 1323 TCP Timestamp option. The default behavior of the TCP/IP stack is to not use the Timestamp options when initiating TCP connections, but use them if the TCP peer that is initiating communication includes them in their synchronize (SYN) segment.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For more information about TCP/IP Registry Values, you could access this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://download.microsoft.com/download/c/2/6/c26893a6-46c7-4b5c-b287-830216597340/tcpip_reg.doc"&gt;http://download.microsoft.com/download/c/2/6/c26893a6-46c7-4b5c-b287-830216597340/tcpip_reg.doc&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 08:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-time-stamp-vulnerability-issue/m-p/2978102#M43327</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2016-12-22T08:51:04Z</dc:date>
    </item>
  </channel>
</rss>

