Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

Enabling our customers to leverage their install base and take them to the next level with Cisco Secure Firewall Threat Defense has always been a key priority.  The migration tool is available for download to migrate the configuration on the on-premi...

gopaks by Cisco Employee
  • 306 Views
  • 0 replies
  • 4 Helpful votes

Resolved! Pix ddenly reboots

Our company has two Cisco PIX 525 Firewalls, one running as "active" andthe otherone running as "failover". The IOS in both of them is 6.1.1.From time to time one the Firewalls suddenly reboots (as shown fromthe syslog pasted in this message

jorantes by Level 1
  • 402 Views
  • 3 replies
  • 0 Helpful votes

I have a corrupt file system on disk0: since I did an erase command (I had to reload the .bin file to get back into the cisco# prompt) but now that it is loaded I cant access disk0: it says its Invalid.... I tried a fsck command to repair the file sy...

chrisbicm by Level 1
  • 2149 Views
  • 3 replies
  • 0 Helpful votes

I setup ID 3110 (suspicious mail attachment)to deny attacker inline thinking that nobody needs to send those type of attachments and it would cut down on virus's. Worked fine until today when someone internal tried to send one and the IPS blocked my ...

I'm trying in vain to upload access-list changes I've made to a startup-config file for a PIX 515 (version 6.3(4).I can't use the copy command at all. When I add a tftp-server line and try "write net startup-config" doesn't work. I go into "config te...

boyd-c by Level 1
  • 932 Views
  • 1 replies
  • 0 Helpful votes

HiJust bought 2 PIX 515E(PIX-515E-UR-BUN) and are about to setup the box. This came out harder then expected :/After connecting my computer to the box, I am unable to aquire ip address, and the manual said there is a built in dhcp server at 192.168.1...

Recently we noticed that the HTTP POST request containing SOAP application is not passed through the PIX (7.1(2)) with default inspection rule.The message is:--------------------------------------------Hypertext Transfer Protocol POST /rcu/rc.asmx...

Here's a question about the mechanics of how the PIX handles ARP (I think!)Assume, just for example, I had a 'standard' PIX installation. 2 interfaces, inside and outside, on standard security levels. I've a number of external IP addresses I can use ...

0r8it by Level 1
  • 834 Views
  • 6 replies
  • 0 Helpful votes

I had a question regarding securing our webservers that use IIS. We have 2 options in play. Which one is a better solution to secure IIS from the IIS vulnerabilities and etc...? I know both have advantages and disadvantages.Here's the setup, a Cis...

jliscano by Level 1
  • 451 Views
  • 3 replies
  • 0 Helpful votes

Hi,i have an asa5501.I need to perform this:limit traffic on an interface (C class subnet) in some hours.Actualy i perform this by a 2611 router, with command rate-limit ..ACL ...., but i can't perform with schedule, i have only 'fixed' limit.Any ide...

pelitti by Level 1
  • 564 Views
  • 3 replies
  • 0 Helpful votes

Just starting out trying to tune some signatures to fit our environment, and looking for clarification on some parameters of IDS signatures.For example: 2152 - ICMP floodIt uses the "Flood Host" engine with the action parameters:Limit type: percent...

jkell by Level 1
  • 563 Views
  • 3 replies
  • 0 Helpful votes

Hello,I just got a new registration key from Cisco by using my Serial Number (we had some problems with the memory getting erased) I was just wondering if anyone knew the exact command to load the new key onto my ASA 5520??Thanks,Chris

chrisbicm by Level 1
  • 1621 Views
  • 5 replies
  • 0 Helpful votes

Hi everyone, I have the following case:2 x Cat6509 (HSRP master and slave)2 x IDSM blades (v5.0 - 229)each Cat has his own IDSM blade install online (not inline), with 2 monitoring sessions on each Cat.There is any way to monitor traffic over 600 Mbp...