Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Adaptive Security Appliance, Secure Firewall Management Center, and Security Cloud Control.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

Hi Everyone,Need to confirm some ASA  concepts below1>For ASA  half form connections the 3 way tcp handshake is never completed and it can cause TCP  SYN  flood attack right?2>To control the limit of half form commection in ASA  we can put config bel...

mahesh18 by Level 7
  • 3261 Views
  • 4 replies
  • 0 Helpful votes

Dear All,I have configured firewall and allow only port 443 and deny all tcp ports for destination, but when i am scanning from port scanner it shows several tcp ports are enabled.. need your seuggestion and help on it.. how to block these tcp ports....

Hi ,Now my current asa 5510 is production as one inside interface (e0/1), one dmz(e0/2) interface and one outside interface(e0/0).I want to add one more isp as outside 1 interface(e0/3).Inside interface(e0/1) I will configure two vlans as one vlan fo...

aung.htwe by Level 2
  • 1416 Views
  • 5 replies
  • 0 Helpful votes

I have an extended access-list rule that is #1 in poistion on the external access listaccess-list acl-outside line 1 extended permit tcp host x.x.x.x host a.b.c.d eq 5723access-list acl-outside line 2 extended permit tcp host x.x.x.y host a.b.c.e eq ...

Dragomir by Level 7
  • 1879 Views
  • 17 replies
  • 0 Helpful votes

Dear FriendsI m getting the following error in ASA in CSM whenever i m clicking on Address Pools,Translation Options & Translation Rules under NAT section.This data for this policy is locked by activity/user: < abc>. After couple of restart and perfo...

Hi allAs topic suggest, i would like to think of deploy a series of cisco product and it is able to mitigate the harm of DDOS. As i know one fo the way is know the source address and route to interfall NULL, but sad ASA can't do interface NULL. My qu...

Hello.What is the recommended way to maintain all incremental IPS signature files created from periodic signature updates? I noticed my small 880 series routers (yeah, I use the cheap IOS IPS) restarts IPS engine for each and every incremental file a...

HQuest by Level 5
  • 1499 Views
  • 2 replies
  • 0 Helpful votes

Good day;        I have a 5505 running pre 8.3 code (8.1) so all the programming is pre new style NAT.        Is there an offline tool I can use to download the config from the 5505, and convert it to 8.4 config to place into the 5512X?     Ideally i...

justin.cohen by Community Member
  • 1933 Views
  • 2 replies
  • 0 Helpful votes

Hi,Aside from all of the normal 8.2 to 8.3 (and above) upgrade issues/concerns that are completely documented elsewhere, I'm wondering if anyone has seen the same issues I have had upgrading ASAs from 8.2(x) to anything above 8.4(x)? The problems bel...

lcaruso by Level 10
  • 427 Views
  • 0 replies
  • 0 Helpful votes

Ok I am pretty new to CISCO configuration. We recently bought an ASA so that we can secure an IIS server behind it. The IIS Server will be doing http and https. I guess I want to do a static nat to nat the outside fixed IP of the website to an intern...

shostackr by Community Member
  • 986 Views
  • 3 replies
  • 0 Helpful votes

Hi allwhen adding a PAT rule on my asa to PAT to the outside Ip of my firewall for internet traffic, Im just monitoring the logs whilst users go on the internet. It appears that I dont see the actual destination they are trying to get to but the IP o...

Review Cisco Networking for a $25 gift card