Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Adaptive Security Appliance, Secure Firewall Management Center, and Security Cloud Control.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

Hi,I have question regarding mixing ACL permit and deny statements. I am using network object-groups. I have a specific requirement. a. I have to permit few port access to servers in object-groupsb  I have to deny all other ports to these servers in ...

S891 by Level 2
  • 601 Views
  • 1 replies
  • 0 Helpful votes

hello,    I just have migrate a 8.0.5 config to a 8.6 and having problem on doing a L2L.    got this error but i can t find where to add the new nat 0 command for exempt traffic.     some one can help ? interface GigabitEthernet0/0 nameif outside sec...

o.fulbert by Level 1
  • 2127 Views
  • 13 replies
  • 0 Helpful votes

Hi,Most examples of NAT translation using an ASA 8.4 are based on servers within a DMZ. In my case it's not because the mailserver also functions as an data and Active Directory server for my local domain.             If tried to config the ASA for a...

Hi,I am havning somw trouble in configuring NAT on intranet firewall. Below is my scenario and I would appreciate If any one can help me to resolve this issue. here is the my topology:   DMZ Network  - - - - - - - - - External Firewall   - - - - - - ...

Below is an example of the output from a “show access-list” command on the Cisco PIX/ASA.NDC-FW-01# show access-listaccess-list allow-in line 1 extended permit tcp any host <IP_1> eq www (hitcnt=186) 0x67305930access-list allow-in line 2 extended per...

hardware by Level 1
  • 760 Views
  • 2 replies
  • 0 Helpful votes

I have this problem and Comcast is not a help in resolving.We just changed  over to Comcast Business and after changing the outside interface to new IP and setting static route.I have access to internet and everythig appears to be good,However asdm w...

Hi,Can one say why do below error occurs at IKE phase 1 negotation:[Cisco] [IKE] ERROR:  Invalid SA protocol type: 0[Cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. [Cisco] [IKE] ERROR:  Phase 1 negotiation failed d...

I am looking to implement Zone-Based Firewall on some 2900 series routers (2911 and 2921.)  Based on some research I've done it looks like the cisco2911-sec/k9 and cisco2921-sec/k9 bundles should be all I need.  Is this correct, or is there some othe...

mat_rouch by Level 1
  • 4616 Views
  • 2 replies
  • 0 Helpful votes

                   Over the course of the past three days, our ASA 5505 firewall has shut down twice.  I looked through the Field Notices and it looks like this was a problem identified several years ago that was resolved for units built after June 1...

ejbensing by Level 1
  • 1003 Views
  • 1 replies
  • 0 Helpful votes