03-09-2022 04:24 PM
Cisco has been completely worthless. I have tried submitted reputation support tickets but they just get closed automatically. Our emails keep getting blocked and nobody at Cisco will help without a contract number. Can anyone help?
03-09-2022 04:34 PM
Talos?
I wonder if this has anything to do it: FN - 72332 - Firepower Software: Cisco Talos Security Intelligence Updates Might Fail After March 5, 2022
03-09-2022 04:36 PM
I have no idea. I just need to know how to get Cisco's help with this. So far they have been worthless. Any ideas?
03-09-2022 05:14 PM
Ok, me bad. I was barking at the wrong tree.
Once those certificates expire or are removed from the Cisco cloud servers, functions such as Smart Licensing, Threat Grid file analysis, and IP Reputation requests communication will fail to establish secure connections to Cisco and might not operate properly.
Would the above description be close to what you're seeing?
03-09-2022 09:29 PM
This is the link:
https://talosintelligence.com/reputation_center/lookup?search=209.182.211.141
I get this response when I submit a ticket.
This case was resolved by automation due to the submission already having a non-blocking score. By default, a URL/IP address with a Web Reputation of Trusted, Favorable, Neutral, or Questionable should be accessible by our customers. Talos does not improve the reputation of already accessible submissions as this would affect the way our automated system functions. If one of our customers cannot access the submission, that is due to aggressive settings on their side and can only be fixed locally by that customer. If you would like this to be reviewed further, please open a TAC case.
We also get this response
Our worldwide sensor network indicates that spam originated from your IP. In addition, our sensors indicate server access attempts from this IP to mail servers within our Sensor Network. This behavior is indicative of email directory harvesting attempts and also results in reputation impact to the IP. Directory harvest detection fires when you are sending to invalid email addresses. It is possible that your network or a system in your network may be compromised by a trojan spam virus, or perhaps there is an open port 25 through which a spammer may be gaining access and sending out spam. The last possibility is that one of your users is sending spam through the IP. We suggest checking these possibilities to help isolate the root cause of the spam and mail server access attempts originating from your IP. In general, once all issues have been addressed (fixed), reputation recovery can take anywhere from a few hours to just over one week to improve, depending on the specifics of the situation, and how much email volume the IP sends. Complaint ratios determine the amount of risk for receiving mail from an IP, so logically, reputation improves as the ratio of legitimate mails increases with respect to the number of complaints. Speeding up the process is not really possible. Talos Intelligence Reputation is an automated system over which we have very little manual influence.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide