<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSA throws portscan alert in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454932#M90891</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Sorry.  It's version 4.5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Dec 2005 19:46:31 GMT</pubDate>
    <dc:creator>piltze</dc:creator>
    <dc:date>2005-12-22T19:46:31Z</dc:date>
    <item>
      <title>CSA throws portscan alert</title>
      <link>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454930#M90889</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm getting an Alert in CSA, generated by Rule 18, stating that "A portscan was detected Reason: ICMP unreachable.  ICMP: 10.64.100.101 -&amp;gt; 10.65.110.118 type destination_unreachable/03.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The target address (.118) is a voice gateway on a 6509.  I dont see any reason for this to occur.  Thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454930#M90889</guid>
      <dc:creator>piltze</dc:creator>
      <dc:date>2019-03-10T09:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: CSA throws portscan alert</title>
      <link>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454931#M90890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You didn't mention what version of CSA you are running and there are different options for each.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may want to turn off the ICMP deny logging or add your voice gateway to the authorized port scanners. Portscan logging is a different matter and it depends on which version you have. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2005 19:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454931#M90890</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2005-12-19T19:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: CSA throws portscan alert</title>
      <link>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454932#M90891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Sorry.  It's version 4.5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Dec 2005 19:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454932#M90891</guid>
      <dc:creator>piltze</dc:creator>
      <dc:date>2005-12-22T19:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: CSA throws portscan alert</title>
      <link>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454933#M90892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, then make sure you are using the Internal IP Stack hardening module and add your voice gateway to the Authorized Port Scanners network address set.  You also may want to exclude the gateway from the host addresses that are scanned by those rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That may do the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Dec 2005 21:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-throws-portscan-alert/m-p/454933#M90892</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2005-12-22T21:05:22Z</dc:date>
    </item>
  </channel>
</rss>

