Other Security Subjects

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity

Forum Posts

Hi,I would like to know if I can use multiple NAT 0 statements for the same interface e.g inside interface.Presently I am already using a nat (inside) 0 statement with an access list. Now I want to implement a site to site vpn. So I want the new acce...

sunilyk by Level 1
  • 350 Views
  • 5 replies
  • 0 Helpful votes

I am stumped on the cause of TCP Segment Overwrite (sig1300) events that I am seeing on multiple sensors from 3 different servers (to the tune of about 4000 events per day per server). The source port on these events are random, but the destination ...

dblairii by Level 1
  • 536 Views
  • 2 replies
  • 0 Helpful votes

I need some remedial help on the use of regular expressions in built-in sigs. In particular, I am referring to the expressions used in Sig 3115 (Sendmail Header Overflow). I am seeing many false positives and I am trying to figure out just what the ...

dblairii by Level 1
  • 337 Views
  • 1 replies
  • 0 Helpful votes

I have certain routers that I want to monitor. However, rather than being alarmed only certain traffic, I want to be notified when there is traffic to/from the device that is NOT SNMP(161) or Syslog(514). Is this possible and is it practical?I am no...

dblairii by Level 1
  • 220 Views
  • 1 replies
  • 0 Helpful votes

Hello All,Have a problem I am looking for help on.I have a pix506e V6.1(4) software and two spanking new pix 525's ( v6.3(1) ).I can use my pdm succesfully to the 506e with use of the following 3 basic commands:pdm location x.x.x.x 255.255.255.255 in...

I have recently had some issues that appeared to be a DOS attack on our network. We currently have an outside company maintaining our PIX and I wanted to verify some information that was given to me from this company. We are converting from a Frame...

bbeck by Level 1
  • 257 Views
  • 2 replies
  • 0 Helpful votes

Resolved! Custom Signature

Can someone help me with this?I am trying to create a custom signature with the following characteristics...Option 1:Source Sequence number is 0Flags are Syn/AckDestination Port 80MinHits 5Option 2Source Port 80Flag RSTSequence number = 1TCP ZeroWind...

bfl1 by Level 1
  • 336 Views
  • 4 replies
  • 0 Helpful votes

Hi All,I'm running Security Monitor 1.2 on CiscoWorks Common Services 2.2 with the latest Signature update (S65). When I select Monitor/Events/today's date, the alarms from yesterday are in the count as well. This has been happening for awhile and ...

ddinh by Level 1
  • 352 Views
  • 3 replies
  • 0 Helpful votes

I would like to create a signature that would ignore all incoming traffic destined for port 53 from certain IP addresses. I would allow all, but we are not that trusting. Also, I would like to allow any traffic destined to certain IP address access...

dpatkins by Level 1
  • 346 Views
  • 3 replies
  • 0 Helpful votes