Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect, Duo, Umbrella, Secure Access and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

watch here Journey banner_2

Browse the Community

Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace

33543 Posts

Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Ada...

72386 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3560 Posts

OpenDNS

Ask questions not covered by support articles and documentation.

3526 Posts

Activity in Security

NAC using Hybrid Joined Devices with Entra and On Prem

Hello Greg, @Greg Gibbs  If User Device is Entra Joined and Users are Entra Joined and AD Joined in other words Hybrid is this use case is tested with ISE ? Is there a reference document you can share ? If users are Hybrid joined can we still do NAC ...

MSJ1 by Level 1
  • 98 Views
  • 0 replies
  • 0 Helpful votes

Single ISE guest portal and multiple global PSNs

We have a global deployment of multiples PSNs ( 2 US-WEST, 2 US-EAST, 2 EU and 2 APAC). Currently we have a single guest hotspot portal with a single URL (guest.portal.XXXXX.com). Each site has a local FortiGate which acts as the DHCP server and a lo...

adias1287 by Level 1
  • 250 Views
  • 4 replies
  • 0 Helpful votes

DDOS protection services - how do they work

Hi AllI am currently looking into ddos protection services to protect some main internet links.What options are out there? I assume it would need to be further up the chain i.e in the ISP / Cloud ? Also, I see lots of them use BGP flowspec, what trig...

Beware: FTD 1120 7.0.8 hotfix is not working

I upgraded from 7.0.8.1-4 to 7.0.8.2-2, the pre-check was OK but I encountered the following error in the log file: EXPORT ERROR: The source parameter ("/var/cisco/deploy/sandbox/snort3-pkg/usr/local/sf/bin/snort-75-3.1.0.800-9") did not pass the Typ...

Emefio by Level 1
  • 120 Views
  • 1 replies
  • 0 Helpful votes

Duo Restore without Google Drive

Hello! I’m using Duo Authenticator on my mobile but trying to move away from Google ecosystem. The Duo Restore functionality is really neat, but I couldn’t find a way to set it to backup to another cloud service (e.g. Nextcloud) or even locally. Is t...

Late1 by Level 1
  • 4717 Views
  • 10 replies
  • 1 Helpful votes

ISE Administration Node Replacement

Morning Cisco Forums,I'm looking for some guidance on the process of replacing ISE administration nodes, in a 4 node cluster.  In our current environment, we're running ISE version 3.4p4, and have a primary/secondary administration node, and 2 policy...

Inq_J by Level 1
  • 375 Views
  • 8 replies
  • 0 Helpful votes

FTD Prevent IP addresses from being shunned

I have some firewalls running FDM locally and not managed by an FMC that keep shunning specific IP Addresses. How do I configure the FTD to prevent these IP addresses from being shunned like you can in an ASA or with the FMC?

SNA redundant site and HA

I need to use on-prem SAL to increase FMC events retention on SNA and need to provide high availability between two data centers for my deployment. i also have have cisco telemetry broker. Would it be the same if 1- i configured ftd syslog to point t...

ASA Firewall Assessment

On GitHub is available a new firewall analyzer tool: https://github.com/WatchThisFirewall/WTF.v1Watch-This-Firewall is a firewall assessment tool designed to connect to firewalls and perform a comprehensive analysis of their configurations. It checks...

Resolved! ASA External Interface Lease renewal ?

Hi folks, We have a ASA on 9.12(4)67. There is an  ONT that is connected on the external interface and we use DHCP to retrieve our IP and gateway etc. for out internet connection. If this interface drops and then recovers (ONT is in a different room ...