Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect, Duo, Umbrella, Secure Access and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Browse the Community

Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace

33826 Posts

Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Ada...

72728 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3677 Posts

OpenDNS

Ask questions not covered by support articles and documentation.

3636 Posts

Activity in Security

Duo for Windows Logon 6.0.0 Released 2026-09-03

Here are release notes for new Duo Downloadable software released today:Duo for Windows Logon 6.0.0 - September 3, 2026General Availability of Offline Access for Passwordless OS Logon.Adds the Duo WinLogon Support Tool, a graphical diagnostic applica...

DuoKristina by Cisco Employee
  • 423 Views
  • 4 replies
  • 1 Helpful votes

Timing of the “clear crypto sa” Command During a Failure

In a policy-based IPsec redundant configuration, if Router 1 fails, an IPsec SA inconsistency occurs between Router 2 and the remote VPN device, preventing communication from resuming. Therefore, we have automated the execution of the clear command v...

CHISHIUNG by Level 3
  • 73 Views
  • 2 replies
  • 0 Helpful votes

Migrate deployment ISE - Procedure and CAs doubts

I need to migrate a Cisco ISE deployment consisting of 1 PAN, 1 SAN, and 3 PSNs, for a total of 5 nodes. The goal is to move all VMs from VMware to Nutanix.My migration plan is to first move the PSNs one by one, verifying that services are operating ...

SupportAC by Level 4
  • 93 Views
  • 4 replies
  • 0 Helpful votes

Resolved! Download VPN Client from FTD

I have configured RAVPN and I am trying to access the outside of the firewall to download the VPN client. I put in the url setup to access to outside interface of the firewall but can't get any reply. I am pretty sure I have everthing configured as r...

sa lifetimes

hi,can someone exaplain to me what happens in the negociations when different sa lifetimes are configured between two vpn peers, ( either the ipsec and ike lifetimes are not the same between peers )thanks in advance

nhedhili by Level 2
  • 1657 Views
  • 5 replies
  • 0 Helpful votes

ise admin user password expiry mail issue

Not receiving mail before x days for admin users password expire from iseadminportal@FQDN and we have smtp server in ise but have another mail id but what should i do for receiving mail before password expiration of ise admin users

FDM-Managed FTD: Syslog Messages Missing Hostname / Device ID

I am troubleshooting an issue where syslog messages from a firewall do not include the configured hostname or any other device identifier.The affected device is a Cisco Secure Firewall 1220CX running FTD 7.6.2-329.The hostname is configured on the de...

jhma by Community Member
  • 60 Views
  • 1 replies
  • 0 Helpful votes

Resolved! IPsec Anti-Replay Errors on ISR 4451 Across Multiple ISPs

Good afternoon,We are experiencing massive and persistent anti-replay errors:%IPSEC-3-REPLAY_ERROR: IPSec SA receives anti-replay error, DP Handle 11, src_addr 192.168.46.5, dest_addr 192.168.46.3, SPI 0x96ddd296 QFP:0.0 Thread:002 TS:000236450936231...

nazar_y by Frequent Visitor
  • 280 Views
  • 3 replies
  • 0 Helpful votes

issue with security intelligence

 In fmc version 10 i see this critical alert Security Intelligence2 System feeds failedresponse processing failed for Cisco_DNS_Intelligence_Feedresponse processing failed for Sourcefire_Intelligence_Feedi logged in the fmc cli and i can connect to u...

Teofanis by Visitor
  • 114 Views
  • 3 replies
  • 0 Helpful votes

Resolved! ASA- Why Dynamic NAT & PAT are unidirectional

I’m a bit confused about Dynamic NAT and PAT on Cisco ASA.When I configure Dynamic NAT/PAT, an inside host initiates a connection to an outside host, and the ASA creates a translation and connection/state entry.My question is: if a new connection/req...

soheb by Community Member
  • 199 Views
  • 5 replies
  • 0 Helpful votes

Migrate FPR 2100 to FPR 3105

I am trying to migrate FPR 2100 FTD to FPR 3105 FTD. Both of them are managed by the same FMC. The FPR3105 has only one configured interface: the management interface. When I use the migration from the FMC, it fails after mapping the interface. Any r...