Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Adaptive Security Appliance, Secure Firewall Management Center, and Security Cloud Control.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

I have problem with configuring the alarms on IDS 4.1 when ACL violation syslog message is received. I have simple config on the router:access-list 120 deny ip any host 10.10.17.254 logaccess-list 120 permit ip any anyinterface Ethernet0/0 ip address...

k.lapczuk by Level 3
  • 1244 Views
  • 2 replies
  • 0 Helpful votes

I have the task of upgradeing a couple of pix 515 firewalls in failover mode from OS version 5.1 to 6.3X. I have looked for a best practice procedure for this but have not found one. Here is what I am thinking:1. shut down primary, let secondary take...

philg by Community Member
  • 993 Views
  • 4 replies
  • 0 Helpful votes

Wondering if CSA agent for Linux is available yet? If yes, In our scenario we have two web sersers are in DMZ segment and once one is active and other is passive mode and is waiting for failover, question is do I need separate csa agent for active an...

umesh.padhye by Community Member
  • 1275 Views
  • 4 replies
  • 0 Helpful votes

What engine parameters would be acceptable to tune out false positives. I do understand that this is network specific, but was looking for other's averages. SERVICE.SMB (6255)? I'm thinking HitCount= ~25FLOOD.NET (UDP)? I'm thinking Rate=4900FLOOD.NE...

rpmanning by Community Member
  • 1070 Views
  • 2 replies
  • 0 Helpful votes

We have 2 4235 NIDS devices that are run by a Security Monitor VMS server. Up until version S128 we were able to upgrade both devices through the MC, however this function has stopped working. The subsequent updates (S129 thru S135) appear to have wo...

ryan.brennan by Community Member
  • 4108 Views
  • 23 replies
  • 0 Helpful votes

I am trying a new code, 12.3.11T2 on our routers and every night when traffic is low, the spoke router with the new code on it would lose it EIGRP adjacencies. All the other spoke that are running 12.3.6a run fine. And the only way to get the neighbo...

qnguyen8 by Frequent Visitor
  • 4411 Views
  • 25 replies
  • 0 Helpful votes

HiWhen I initial setup ids 4235 and installed IDS MC 1.2 completed.I want import the sensor into IDS MC,when I add sensor by select device>sensor and fill the blank request and select next,my browser stoped.When you open control panel>service:tomcat....

wei.xiong by Community Member
  • 837 Views
  • 1 replies
  • 0 Helpful votes

I was reading the “Virtual Private Networks in Depth” Cisco Safe document and I found the following sentence:“All VPN devices should use the NTP protocol (using authenticated NTP) to synchronize the time.”However, I couldn’t find any way to enable th...

obrenes by Community Member
  • 1246 Views
  • 2 replies
  • 0 Helpful votes

Hello, I have a PIX 501 that is configured as a DHCP server for some internal hosts consisting of Thin Clients (Neoware and Wyse) and PC's. For the last few weeks, the DHCP service has been acting up and refusing to assign addresses to the Thin Clien...

dro by Level 3
  • 849 Views
  • 2 replies
  • 0 Helpful votes