<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSA: how to detect Security level changes? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007586#M79573</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I'm not mistaken, the proxy &lt;U&gt;was&lt;/U&gt; the issue.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No one was there to click 'yes' when it tried to get updates and when you took the proxy out of the mix it worked, correct? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Jan 2009 05:45:49 GMT</pubDate>
    <dc:creator>tsteger1</dc:creator>
    <dc:date>2009-01-07T05:45:49Z</dc:date>
    <item>
      <title>CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007575#M79557</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;Does anybody know how to detect security level changes made in Agent UI by the end user? I need some kind of the 'flag' which would indicate that security level was changed form High to Medium manually.&lt;/P&gt;&lt;P&gt;All that I'm tring to do is to add some kind of intelligence to CSA. When roaming user is connected to guest network security level must be automatically set to High. That was a pretty trivial task to do.&lt;/P&gt;&lt;P&gt;But CSA Agent must allow user to set less restrictive setting (Medium or Low, let's say for 12 hours). And this part is a real catch. I didn't find any ways to "explain" to CSA that user has changed settings.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007575#M79557</guid>
      <dc:creator>asp13</dc:creator>
      <dc:date>2019-03-10T11:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007576#M79561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on which version you are using.  Version 5.2 lists what security level agents currently are and you can change them back manually from the MC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also set up an alert to notify you when someone changes the security level with the UI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jul 2008 00:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007576#M79561</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2008-07-08T00:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007577#M79562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me what's the method to create&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Rule to make the security level to high by default &lt;/P&gt;&lt;P&gt;2) An alert for the security level change on the end user machines.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Dec 2008 18:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007577#M79562</guid>
      <dc:creator>sampathsundararajan</dc:creator>
      <dc:date>2008-12-17T18:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007578#M79563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.  You would need to have the security level set by a triggering rule. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use a system state that is sure to fire like "Ethernet Active" and create a set rule to change the security level to high.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.  Create an event set with the severity of "Notice" for the rule module with your agent service control rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create an alert that sends an email when the event set gets a new event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't want users to change the security level, create an Agent Control rule that denies it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Dec 2008 19:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007578#M79563</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2008-12-18T19:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007579#M79564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Tom,Also I would like to know, where and how I can set the proxy on the CSA MC for the CLAM AV.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could not find any setting on the CSA MC, so that CSA MC can download updates from CLAM AV website.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Dec 2008 19:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007579#M79564</guid>
      <dc:creator>sampathsundararajan</dc:creator>
      <dc:date>2008-12-18T19:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007580#M79566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are quite welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can either exempt the MC from the proxy server or allow http connections to db.local.clamav.net.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Dec 2008 07:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007580#M79566</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2008-12-20T07:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007581#M79567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any rule to do that or where should be say on the MC that it has go thru proxy server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Dec 2008 14:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007581#M79567</guid>
      <dc:creator>sampathsundararajan</dc:creator>
      <dc:date>2008-12-20T14:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007582#M79568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSA is not blocking signature updates, your proxy server is.  My MC is able to obtain sigatures with no trouble.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the online help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;In order for the CSA MC to obtain signature updates from ClamAV server (db.local.clamav.net) should be reachable over HTTP either directly or through proxy server.&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means you need to configure your proxy server to allow connections to that address or you need to exempt the MC from the proxy server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 18:35:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007582#M79568</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2008-12-22T18:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007583#M79569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi tom&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I was reading this topic, and I have a doubt, do you need  configure to CSA MC  to going to the db.local.clamav.net for the update, in this case where I can do this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jan 2009 22:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007583#M79569</guid>
      <dc:creator>dflores83</dc:creator>
      <dc:date>2009-01-05T22:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007584#M79571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David, it is already configured to go there for updates.  Your MC just needs to be able to reach it via HTTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam's MC was not able to reach it because of a proxy server issue.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully he will post back when he solves the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 06:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007584#M79571</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2009-01-06T06:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007585#M79572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Tom, &lt;/P&gt;&lt;P&gt;I did not have any issue as such with the proxy. There was a query for me, whether it can go thru the proxy. Now we are not going through the proxy. It's direct connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your suggesstion. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2009 15:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007585#M79572</guid>
      <dc:creator>sampathsundararajan</dc:creator>
      <dc:date>2009-01-06T15:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: CSA: how to detect Security level changes?</title>
      <link>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007586#M79573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I'm not mistaken, the proxy &lt;U&gt;was&lt;/U&gt; the issue.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No one was there to click 'yes' when it tried to get updates and when you took the proxy out of the mix it worked, correct? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2009 05:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-how-to-detect-security-level-changes/m-p/1007586#M79573</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2009-01-07T05:45:49Z</dc:date>
    </item>
  </channel>
</rss>

