<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSA MC 51 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863889#M85379</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul, thanks for the kind words and rating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will certainly keep this in mind if I decide to pursue a new career path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Nov 2007 00:16:28 GMT</pubDate>
    <dc:creator>tsteger1</dc:creator>
    <dc:date>2007-11-14T00:16:28Z</dc:date>
    <item>
      <title>CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863877#M85364</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have CSA MC 5.1 runing and want to denay all spyware and some network access (snipping,icmp) to deny. I created customs Policies with rule modules for Application Install and network access and given Prioty Deny as Action but still I can install applications but i can't uninstall them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise how to create a rule and deny Install/access/ some applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863877#M85364</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2019-03-10T10:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863878#M85365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Network Access Control rules should be fairly straightforward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is your application install deny rule configured?  That one is trickier.&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;You should enable logging and test *only* those rules on a host and see if they work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 17:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863878#M85365</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-11-05T17:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863879#M85366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for prompt reply. Having deny rules configured I tried to install Googletalk and it worked, apparently I was not able to uninstall the same.That's way I wonder how it installed?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I only custormized Install Application rule module and Network access rule module and put them in new policy. The Group which host was associated is neither Test nor Learn mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is the logs I found in my SCA MC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I need to block any spayware applications and deny icmp,port scan applications. Kindly advise me the procedure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate if you can advise me the steps in order to do the above tasks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2007 19:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863879#M85366</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2007-11-05T19:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863880#M85367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a written policy that forbids users to install unauthorized software?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ask because your example is not spyware, it's a chat program that users must install or access through a browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Blocking ICMP and port scanning can be done with the System Hardening and Personal Firewall Modules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Identifying and blocking specific spyware with CSA is difficult to do and keep it up to date.  &lt;/P&gt;&lt;P&gt;CSA is better for protecting machines from the undesirable side effects of spyware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO it's better to deploy an AV/AntiSpyware package to protect and clean.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to track or block specific applications, you can do that with file access control rules using the filenames associated with the package.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this particular app, you could block googletalk-setup.exe and all .exe's in the google talk folder.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enterprising users could find ways around this but if you have written policy to back it up, they might be less inclined to try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2007 00:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863880#M85367</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-11-06T00:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863881#M85368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not have written policy to forbids install unauthorized software. I only did copying Install Application rule modules and made Action as Priority Deny. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please tell me the steps how to block installing any unthorized softwares ?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try blocking ICMP and port scanning with the System Hardening &amp;amp; Personal Firewall modules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2007 05:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863881#M85368</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2007-11-06T05:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863882#M85369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pemasiri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want to suggest anything too broad because I don't know what your environment is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure which Application Install module you used so I can't tell you why it doesn't work.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the rule queries a user when desktop interface applications invoke executables.  &lt;/P&gt;&lt;P&gt;It also looks like you denied that ability to answer a queries so it takes the default action.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should check your agent UI or users states.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the method in my previous post with file access controls to block specific applications or deny installs with group policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2007 21:01:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863882#M85369</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-11-06T21:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863883#M85370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use this CSA5.1 in our company mostly for Windows Desktop and Servers. Also we are planning to have different groups according to our nature of business. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Application Controll module, Application Access and Network Access modules and its rules I configured are attached here for your references.I can see some counts under Events colums like 21 (0) but don't know how &amp;amp; why its.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not configured denying any quries answered by users &amp;amp; infact I did not get that queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I need is to block/deny installing any software and deny ICMP,port scanning application to run on my network by the users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly tell me how to do the above needful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2007 12:31:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863883#M85370</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2007-11-07T12:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863884#M85371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the attachement again with configured rules.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2007 12:35:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863884#M85371</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2007-11-07T12:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863885#M85372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pemasiri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The event columns show the total number of events for the rule and all events in the last 24 hours in parentheses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason you haven't seen queries is because you (the administrator) have prohibited user interaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look at the first screenshot you posted (Nov 5) and you'll see where queries are answered with the default "no" because of this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to enable the Agent UI and isolate the rules you want to test to make sure there are no others stepping on them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Honestly, I can't really tell you more than that about how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, &lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2007 19:35:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863885#M85372</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-11-07T19:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863886#M85374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry to troubling you. My problem is still the same inspite your advices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made changes to a File access controll rule module and add File set Instant messanger executables and add googletalk-setup.exe in same set (see attached) but even then I could install googletalk by Allowing the user query. But I do not need any user queries while installing any applications. I have made those fille access rules action as "Deny" not "Querry user" but I dont know why still getting that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i check my logs I can see all those actions have appeared as "Operation was denied" but i was able to install the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I copied Personnel Firewall module and System hardening modules and made most of network/system access rules as "Deny" but I still can do ICMP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In brief all I want to do is disallow any unauthorized software installaing, ICMP and any portscanning software to run by my company uers.&lt;/P&gt;&lt;P&gt;Please advise how to do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Nov 2007 10:42:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863886#M85374</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2007-11-11T10:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863887#M85376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are the Man! By simply reading through your attempts to troubleshoot this problem from halfway around the world I learned quite a bit. I rated it a 5+.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep up the good work! If you ever want to become a consultant and do this sort of work full time please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Nov 2007 13:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863887#M85376</guid>
      <dc:creator>pmccubbin</dc:creator>
      <dc:date>2007-11-11T13:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863888#M85378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pemasiri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have good news and bad news...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First the good news,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The googletalk install rule could work as a deny instead of a query but you need to find the rule (using the specific event) and change it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the bad news...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other rules in your screenshots will deny many MS installs but have never been triggered probably because there are other allow rules superceding them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If these rules ever do take effect, you won't be able to do MS updates and a lot of other things because you denied access to all files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My suggestion would be to take a step back, take a deep breath and either try to undo all the changes you've made and start again or install a test MC in order to figure all this out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a way to do this but I'm afraid the rules are a bit confused now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck, Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2007 19:05:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863888#M85378</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-11-13T19:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: CSA MC 51</title>
      <link>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863889#M85379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul, thanks for the kind words and rating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will certainly keep this in mind if I decide to pursue a new career path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2007 00:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-mc-51/m-p/863889#M85379</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-11-14T00:16:28Z</dc:date>
    </item>
  </channel>
</rss>

