Security Knowledge Base

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Webinar

 
Labels

Knowledge Base Articles

What is NAT-T?Any incoming packets (which come directly from unsolicited sources) would be blocked by such a NAT appliance, as the internal PC’s and IP phone extensions are non-routable from the public network. But most of the incoming calls in IP Te...

TCC_2 by Community Member
  • 11831 Views
  • 0 comments
  • 0 Helpful votes

Core issueThis issue occurs due to the presence of Cisco bug ID CSCse52050.The problem occurs when Cisco PIX or ASA that runs software release 7.0, 7.1, or 7.2 configured with a very large access-list applied to either a nat statement or a Crypto Mat...

TCC_2 by Community Member
  • 1232 Views
  • 0 comments
  • 0 Helpful votes

ResolutionTo block the installation of new applications by non-administrators, perform these steps:Create a blank deny for program installation.Create an allow rule, with a user state condition that states to only apply this rule if an administrator ...

TCC_2 by Community Member
  • 1258 Views
  • 0 comments
  • 0 Helpful votes

ResolutionScenario 1:This is the sequence in which the translation commands are prioritized by the PIX Firewall:nat 0 access-list (nat-exempt) match against existing xlates static statementsstatic nat with and without access-list (first match) static...

TCC_2 by Community Member
  • 6304 Views
  • 0 comments
  • 0 Helpful votes

Core issueWhen the ESMTP application inspection feature is enabled, the PIX Firewall allows mail servers to receive the fifteen commands, while it rejects all other commands and never sends them to the mail server.Extended Simple Mail Transfer Protoc...

TCC_2 by Community Member
  • 2302 Views
  • 0 comments
  • 0 Helpful votes

ResolutionThe PIX Firewall knows how many hops are needed to reach a certain destination, but it cannot advertise this information. The PIX does not support a command nor configuration settings to advertise global addresses or networks outside of the...

TCC_2 by Community Member
  • 1090 Views
  • 0 comments
  • 0 Helpful votes

Core issuePIX Device Manager (PDM) versions 3.0(1), 3.0(2), 4.0(1), and 4.1(1) are incompatible with Java Plug-in versions 1.4.2_08 and 1.5.0_02 or later. If PDM is accessed from a computer workstation with these Java Plug-ins or later versions of Ja...

TCC_2 by Community Member
  • 16481 Views
  • 0 comments
  • 0 Helpful votes

Core issueIntermediate device is blocking IPSec traffic between the client and the PIX.ResolutionPerform the following steps.Issue the show crypto ipsec sa command.Identify your connection entry.Check the encrypt and decrypt counters.If you see no de...

TCC_2 by Community Member
  • 983 Views
  • 0 comments
  • 0 Helpful votes

Core issueThe CCA solution comprises three main components:  One or more CCA Servers  A CCA Manager  Optional CCA AgentsCustomers configure the solution using a web-based interface on the CCA Manager and the CCA Manager distributes that configuration...

TCC_2 by Community Member
  • 1952 Views
  • 0 comments
  • 0 Helpful votes

Core issueSince the Adaptive Security Appliance (ASA) 5500 sits behind a Network Address Translation (NAT)/Port Address Translation (PAT) device, the VPN peers (clients as well as LAN-to-LAN peers) either cannot connect or cannot pass traffic.Encapsu...

TCC_2 by Community Member
  • 3985 Views
  • 0 comments
  • 0 Helpful votes
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Top Contributors
Featured Article