10-06-2020 03:32 AM
I'm new to dealing with the FMC and FTD, and new to working directly with Cisco Products in general, but I'm wondering if anyone could point me in the right direction regarding detection for ARP Poisoning from the FTD appliance.
So far, I have tried to create a Correlation Rule, which did not work in detecting ARP Poisoning. I have also discovered that the underlying IDS of the FTD is Snort, which does have a preprocessor for detecting ARP Poisoning, however, I cannot see it within the list of preprocessors. I have also noticed some ARP Poison related signatures in the "DELETED" folder in Intrusion Rules.
Basically my questions are:
Any and all help will be much appreciated!
10-06-2020 04:39 AM
10-06-2020 05:51 AM
Hi Mohammed,
Thank you for the response!
So are you saying that the FTD appliance needs to be in Transparent mode and then I would also need to set up the DAI feature on the switches along with DHCP Snooping to make ARP Poisoning detectable within the FMC? Or are the DAI and DHCP Snooping features just a mitigation technique?
Cheers.
10-06-2020 07:07 AM
10-07-2020 01:27 AM
Thank you for you help Mohammed!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide