Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

I have a Cisco 880 and try to establish an IPsec VPN dialin in combination with zone based firewalling.The IPsec dialin works fine without any issues which was crosschecked before activating the ZFW.ZFW config looks like this:!class-map type inspect ...

pfoerster by Level 1
  • 474 Views
  • 0 replies
  • 0 Helpful votes

Hey all, Somewhat of a silly question when it comes to identity NAT rules, which cause the ASA to use NAT divert instead of the routing rable. How does the ASA determine the next-hop IP address in this scenario? We currently are dual homing our ASA t...

So I need to allow a server in the DMZ to talk to a domain controller on the internal network for authentication.  This requires allowing a bunch of protocols through the firewall, some googling I think has given me a comprehensize list. That said, h...

I found one link on cisco website explaining a little about virtual reassembly, what I dont understand is when I enable that option on my tunnel interface why I cannot ping packets larger than 1420 from the other end of the tunnel?? When I disable v...

glenthms by Level 1
  • 193431 Views
  • 3 replies
  • 10 Helpful votes

Hello; I am Erdenesukh Magsarjav who is system engineer of Civil Aviation Authority Mongolia. Our organization have bought your system which ASA-5585-10CTRL-LIC next generation firewall with FMC. ASA5585 firewall IOS  9.2 version  ,firepower version ...

I just sat through a teaching where the instructor gave an example of a security issue & how to resolve it. A server on a LAN behind an ASA had 350 IP Addresses attempting to SSH into it over night (brute force attack). The instructer then checked th...

I have a 5506 and I'm trying to get a NAT to work. I have two servers (david and goliath), I want david to get 22,80, 443, goliath to get 444 I added the nats by using the commands below nat (Servers,outside) source static goliath interface service 4...

Alexsc by Level 1
  • 1466 Views
  • 9 replies
  • 0 Helpful votes

With the 3.x being EOL, does that mean 3.x could be used without cost of buying a license PAK?  Or, would I have to purchase the new 4.x PAK in order to increase my anyconnect premium peers?  I've seen the old 5.x client still being used out there, j...

I recently was at a job site were I was supposed to swap a Cisco 1941 with a ASA 5506.  I preconfigured the ASA and tested to make sure it was routing outside properly.  There is a Verizon business 300mbs line coming in to the Router.  When doing a b...

Network.png
Review Cisco Networking for a $25 gift card