cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1352
Views
5
Helpful
1
Replies

Will the Threat grid appliance accept clean, Dirty and Admin interface ip addresses in the same subnet?

nareshbabu.e
Level 1
Level 1

for example 192.168.1.1, 1.2 and 1.3 in /24 subnet

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

While it is technically possible, it is not recommended. Admin and Clean are fine on the same network. Dirty should be on "a dedicated external IP address (i.e., the "Dirty" interface) that is different from your corporate IP, in order to protect your internal network assets."

Reference:

https://www.cisco.com/c/dam/en/us/td/docs/security/amp_threatgrid/threat-grid-appliance-setup-and-config-guide-v2-4-3_2-4-3-3.pdf

Also note that the Dirty interface MUST have a public DNS server - one with no DNS security policy enforcement (like, for instance, an Umbrella server would have)

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

While it is technically possible, it is not recommended. Admin and Clean are fine on the same network. Dirty should be on "a dedicated external IP address (i.e., the "Dirty" interface) that is different from your corporate IP, in order to protect your internal network assets."

Reference:

https://www.cisco.com/c/dam/en/us/td/docs/security/amp_threatgrid/threat-grid-appliance-setup-and-config-guide-v2-4-3_2-4-3-3.pdf

Also note that the Dirty interface MUST have a public DNS server - one with no DNS security policy enforcement (like, for instance, an Umbrella server would have)

Review Cisco Networking for a $25 gift card