Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect, Duo, Umbrella, Secure Access and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Personalize banner_3

Browse the Community

Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace

33687 Posts

Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Ada...

72594 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3620 Posts

OpenDNS

Ask questions not covered by support articles and documentation.

3574 Posts

Activity in Security

Site-to-Site IKEv2 IPSec VPN Implementation

                                                                     Site-to-Site IKEv2 IPSec VPN Implementation Introduction IKEv2 Proposal IKEv2 Policy IKEv2 Keyring IKEv2 Profile Crypto MAP Verification Introduction IPSec VPNs would normally use ...

Blue_Bird_0-1751453480449.png Blue_Bird_1-1751453903784.png Blue_Bird_2-1751453965073.png Blue_Bird_3-1751453992167.png

Cisco AnyConnect Connctvity Issue

Hi Guys,I am currently in the process of migrating the AnyConnect VPN from SSL to IPSec (IKEv2). During the transition period, I have allowed both SSL and IKEv2, and updated the AnyConnect XML profile to use IPSec as the primary protocol. All require...

NetHeads by Visitor
  • 544 Views
  • 1 replies
  • 0 Helpful votes

IPsec Redundancy Using HSRP

We have configured HSRP on the LAN side of the WAN router and are using BGP and IPsec on the WAN side.In this case, is redundancy required in the crypto map for the WAN-side interface?Since HSRP is not used on the WAN side, I believe it is not necess...

CHISHIUNG by Level 2
  • 49 Views
  • 1 replies
  • 0 Helpful votes

Resource Connector 2.0.99-2604291148

This Resource Connector software version contains certain updates:Re-enabled the Resource Connector IP Address Display in the dashboard, giving administrators direct visibility for faster troubleshooting and simplified connectivity management.OS Secu...

adaswani by Cisco Employee
  • 38 Views
  • 0 replies
  • 0 Helpful votes

Hidden Admin Object

Hello Community,When I go to:Users -> Users - No user exist.Users -> Administrators -> Administrators -> Add Administrator - It states the provided email address is already in use by another admin. How to remove hidden admin object?Regards,AK

amit0223k by Community Member
  • 217 Views
  • 2 replies
  • 0 Helpful votes

Duo for RD Gateway 3.0.0 Released 2026-MAY-04

May the fourth be with you! Here are the release notes for new Duo downloadable software released today.Duo for Remote Desktop Gateway 3.0.0 - May 4, 2026Adds certificate pinning support to enhance security of the connection between the Duo RD Gatewa...

DuoKristina by Cisco Employee
  • 97 Views
  • 0 replies
  • 1 Helpful votes

Cisco Deprecating Google Authenticator?

Got caught off guard on this one.Cisco is mandating everyone use MFA on all their Cisco accounts. I get that, encourage it even.Today I get an email."Security Cloud Sign On now requires Duo as the only supported multi-factor authentication (MFA) meth...

kalanfuga22 by Community Member
  • 217 Views
  • 2 replies
  • 0 Helpful votes

Resolved! PassiveID problems

Hi there,Im having som trouble setting up PassiveID in a new ISE install.ise version 3.4 patch 4I have 3 nodes, all of them have passiveid enabled, and i can see the service running in cli with 'sh app stat ise'in the ise passiveid-agent.log i see th...

Janne K. by Level 4
  • 922 Views
  • 5 replies
  • 0 Helpful votes

OFFLINE MODE

Hello,Is it possible to continue using two-factor authentication on DUO applications that use RADIUS via the DUO proxy and on applications via DNG? I know this is possible with Windows logon, but I haven’t yet tested it with the other options.

Alex2025 by Spotlight
  • 148 Views
  • 2 replies
  • 0 Helpful votes

Replace Firepower 4110 with Firepower 3130

I am going to replace my existing Firepower 4110 appliance running FTD 7.0.9 let call it with the name fp4110, managed by the FMC running 7.4.7, with a new Firepower 3130 appliance, let call it fp3130. All existing IP address(es) with the exception o...