Security Knowledge Base

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Webinar

 
Labels

Knowledge Base Articles

Core issueThe flow of traffic from the hosts and workstations behind the PIX Firewall to the Internet is interrupted in this situation. The flow is interrupted because PIX does not follow the xlate timer defined with the xlate timeout command. The tr...

TCC_2 by Level 10
  • 844 Views
  • 0 comments
  • 0 Helpful votes

Core issueThe issue is documented in Cisco bug ID CSCsc39334.ResolutionFor a workaround, remove the check-retransmission command from the tcp-map.As an alternative, upgrade to any of th software versions. Refer to Software Downloads: Cisco PIX Securi...

TCC_2 by Level 10
  • 704 Views
  • 0 comments
  • 0 Helpful votes

ResolutionYou can define multiple addresses for a peer to connect as back-up when the IPSec tunnel to the primary headend device fails. this is an example:crypto map VPN 10 ipsec-isakmpset peer 192.167.1.6 !--- The primary headend.  set peer 192.168....

TCC_2 by Level 10
  • 3641 Views
  • 0 comments
  • 0 Helpful votes

ResolutionConduit:The conduit command is used in order to permit or deny inbound connections through the PIX Firewall. The conduit command functions with the creation of an exception to the PIX Adaptive Security Algorithm that permits connections fro...

TCC_2 by Level 10
  • 6066 Views
  • 0 comments
  • 0 Helpful votes

Core issueThis problem occurs due to the presence of Cisco bug ID CSCse14296.The VPN Client is not able to connect to Cisco ASA 7.2(1) if the root certificate authority (CA) has two subordinate CAs. The ASA identity certificate and the VPN Client ide...

TCC_2 by Level 10
  • 1214 Views
  • 0 comments
  • 0 Helpful votes

Core issueThis problem was first seen with CiscoSecure ACS for Windows version 3.2(1.20). This issue occurs due to the presence of Cisco bug ID CSCec26584.CiscoSecure ACS for Windows currently supports EAP for only four RADIUS types (Internet Enginee...

TCC_2 by Level 10
  • 620 Views
  • 0 comments
  • 0 Helpful votes

ResolutionIn order to upgrade the Cisco Security Monitoring Analysis and Response System (CS-MARS) with CD or DVD ROM, complete these steps. In this example, the upgrade is from version 4.2.2 to 4.2.3. The pkg file used for the upgrade exists on the ...

TCC_2 by Level 10
  • 2013 Views
  • 0 comments
  • 0 Helpful votes

Core issueThis happens because broadcasts do not go through an IPSec tunnel.Browsing Network Neighborhood is a function of the Microsoft browsing service. Any problems are usually because the PC or master browsers do not function properly. Network Ne...

TCC_2 by Level 10
  • 3145 Views
  • 0 comments
  • 0 Helpful votes

Core issueThere might be many reasons if downloadable ACLs are not pushed or are unable to restrict access for VPN Clients. But , one of the common reasons is if the sysopt ipsec pl-compatible command is configured on the PIX Firewall.In such a case,...

TCC_2 by Level 10
  • 1707 Views
  • 0 comments
  • 0 Helpful votes

Core issueThe VPN client fails to connect to the headend if it passes through a NATting or a PATting device. This issue occurs if inspection for IPsec traffic is not enabled on the passthrough device. When this issue occurs, the regular translation c...

TCC_2 by Level 10
  • 4795 Views
  • 0 comments
  • 0 Helpful votes
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Top Contributors
Featured Article