<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSA 4.5 and SMS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431829#M99308</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We also run SMS, and have a File Access Control Rule that allows the  Scanwrapper.exe located at @system\CCM\** to prety much do anything it wants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems like Scanwrapper.exe is the initiating process that starts SMS off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Brad Foy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Jun 2005 04:59:51 GMT</pubDate>
    <dc:creator>nrmdcs</dc:creator>
    <dc:date>2005-06-08T04:59:51Z</dc:date>
    <item>
      <title>CSA 4.5 and SMS</title>
      <link>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431825#M99304</link>
      <description>&lt;P&gt;Is there a way in the new CSA 4.5 to allow anything to run on a client PC if it came from a specific server?  We have a SMS server that needs to be allowed to run whatever it needs to on all our computers.  I saw under system state there is a 'network address ranges' but I'm not sure if this would do it or not. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431825#M99304</guid>
      <dc:creator>mbarasch</dc:creator>
      <dc:date>2019-03-10T09:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 4.5 and SMS</title>
      <link>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431826#M99305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have specific servers that are allowed to connect to hosts and/or run network services on certain ports and we used the network address ranges to make the exceptions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2005 22:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431826#M99305</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2005-06-06T22:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 4.5 and SMS</title>
      <link>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431827#M99306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was told yesterday that the network address ranges under a System State rule applies to the ip address that's running on the client.  Is this correct?  I need it to apply to server that is trying to run the application or network service on the PC that has the agent running. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2005 11:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431827#M99306</guid>
      <dc:creator>mbarasch</dc:creator>
      <dc:date>2005-06-07T11:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 4.5 and SMS</title>
      <link>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431828#M99307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's correct but that's not where you would create the rule.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The system state sets define when a system is more or less vulnerable or on a particular network, etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you need to do is identify what SMS actually does and then create rules to allow it.  Then you can limit where the SMS contact comes from if you want to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2005 23:19:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431828#M99307</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2005-06-07T23:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 4.5 and SMS</title>
      <link>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431829#M99308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We also run SMS, and have a File Access Control Rule that allows the  Scanwrapper.exe located at @system\CCM\** to prety much do anything it wants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems like Scanwrapper.exe is the initiating process that starts SMS off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Brad Foy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2005 04:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-4-5-and-sms/m-p/431829#M99308</guid>
      <dc:creator>nrmdcs</dc:creator>
      <dc:date>2005-06-08T04:59:51Z</dc:date>
    </item>
  </channel>
</rss>

