<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Fails spank.c securty scan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-fails-spank-c-securty-scan/m-p/1137751#M878858</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nice one. i put the following in earlier and will wait for the scan tonight. thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network ALL-MCAST&lt;/P&gt;&lt;P&gt; description Full Multicast Block&lt;/P&gt;&lt;P&gt; network-object 224.0.0.0 240.0.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list outside_acl extended deny ip object-group ALL-MCAST any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Dec 2008 20:34:19 GMT</pubDate>
    <dc:creator>Robert Ho</dc:creator>
    <dc:date>2008-12-12T20:34:19Z</dc:date>
    <item>
      <title>ASA Fails spank.c securty scan</title>
      <link>https://community.cisco.com/t5/network-security/asa-fails-spank-c-securty-scan/m-p/1137749#M878856</link>
      <description>&lt;P&gt;hey all, we have a customer failing the spank.c security scan. there is no multicast enabled on the outside. anyone else have any luck with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.securityspace.com/smysecure/catid.html?id=11901" target="_blank"&gt;http://www.securityspace.com/smysecure/catid.html?id=11901&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-fails-spank-c-securty-scan/m-p/1137749#M878856</guid>
      <dc:creator>Robert Ho</dc:creator>
      <dc:date>2019-03-11T14:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Fails spank.c securty scan</title>
      <link>https://community.cisco.com/t5/network-security/asa-fails-spank-c-securty-scan/m-p/1137750#M878857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Robert,&lt;/P&gt;&lt;P&gt;   Most probably, you have web servers or exchange server that needs a tcp port to be opened in outside interface ACL. Generally the ACE contains&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit tcp any host PublicIP eq tcpport&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   That means this ACE also permits traffic from multicast groups 224.0.0.0 subnet, since source is "any.&lt;/P&gt;&lt;P&gt;   Insert an ACE "before" the ACEs that permit from any source, which is like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;deny ip 224.0.0.0 16.0.0.0 any&lt;/P&gt;&lt;P&gt;permit tcp any host PublicIP eq tcpport&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 20:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-fails-spank-c-securty-scan/m-p/1137750#M878857</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-12-12T20:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Fails spank.c securty scan</title>
      <link>https://community.cisco.com/t5/network-security/asa-fails-spank-c-securty-scan/m-p/1137751#M878858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nice one. i put the following in earlier and will wait for the scan tonight. thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network ALL-MCAST&lt;/P&gt;&lt;P&gt; description Full Multicast Block&lt;/P&gt;&lt;P&gt; network-object 224.0.0.0 240.0.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list outside_acl extended deny ip object-group ALL-MCAST any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 20:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-fails-spank-c-securty-scan/m-p/1137751#M878858</guid>
      <dc:creator>Robert Ho</dc:creator>
      <dc:date>2008-12-12T20:34:19Z</dc:date>
    </item>
  </channel>
</rss>

