Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect, Duo, Umbrella, Secure Access and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Navigation banner_4

Browse the Community

Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace

33780 Posts

Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Ada...

72685 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3665 Posts

OpenDNS

Ask questions not covered by support articles and documentation.

3613 Posts

Activity in Security

Resolved! FTD IKEv2 to Windows 10 Native client with dynamic Group Policies

Dear all, lately I have managed to make FTD to support IKEv2 tunnel from Windows 10 Native client, using only certificate authentication.However the configuration is working only with one locally created address-pool. For SSL we have 3 different Grou...

Resolved! Timing of IPsec Encryption

My understanding is that IPsec encryption takes place on the output interface after routing; however, there are very few resources that explain this mechanism, and I suspect that quite a few engineers mistakenly apply crypto maps to physical interfac...

CHISHIUNG by Level 3
  • 51 Views
  • 1 replies
  • 0 Helpful votes

Resolved! Purpose of the IPsec Local ID

The following local ID is defined in the IPsec configuration. What is its purpose? Please also explain how the system behaves if this setting is omitted.crypto ikev2 profile IKEv2_Profileidentity local key-id IKEv2_VPN

CHISHIUNG by Level 3
  • 100 Views
  • 3 replies
  • 0 Helpful votes

Block access to Google Games

We recently implemented a pair of FW1120's with full FTD licensing.  Configuring access control policies to block specific websites and URL categories.One of the categories we have blocked is "games" which does a great job of blocking those websites....

spauldingd by Frequent Visitor
  • 7467 Views
  • 8 replies
  • 0 Helpful votes

ISE 3.4 Error on creation identities users

I am having trouble creating a TACACS user. We discovered that some accounts had been disabled, and I get an error when trying to re-enable them.It is not an error preventing creation; rather, the system flags this error regardless of the name the us...

iec1128759_0-1785523973742.png

How to set the per-network opendns updater password?

I have a small number of networks using OpenDNS, each with its own per-network updater password (that is, even though three networks are all managed within my one OpenDNS login, the updater client on each network has its own unique password to update...

JayLibove by Community Member
  • 117 Views
  • 0 replies
  • 0 Helpful votes

IPsec/IKEv2 "remote ident" and automatically generated crypto map

Hello,I hope an IPsec/IKEv2 guru will be able to enlighten me.ContextWhile not mandatory for the question, I provide a little bit of context.We use IPsec/IKEv2 tunnels to terminate mobile access of customers into their respective VRF. FlexVPN solutio...

ISE Identity Services Engine authentication method

Dear Team,  Just want to confirm, we created SSID and we're using ISE as a NAC right now we would like to implement double authentication method MAC address, and Active Directory credentials Network team mentioned it is not supportable to implement b...

zain-3-4 by Visitor
  • 343 Views
  • 9 replies
  • 0 Helpful votes

FMC "Product Upgrades" cannot connect to server

Hello!FMC version 7.6.5I have trouble with downloading upgrade packages via FMC UI in "Product Upgrades".After clicking the circle to retrieve available updates, it says "Contacting server" in the bottom left and after a minute or so (sometimes faste...

Robin-H by Frequent Visitor
  • 94 Views
  • 0 replies
  • 0 Helpful votes

CoA Behind IP Phone

I try to switch vlan for an endpoint from my fortinac and if the endpoint connect to the port switch then vlan change is working, i can see the nac send the coa and cisco switch receive the coa. When the endpoint connected behind the ip phone then wh...

hs08 by VIP
  • 126 Views
  • 3 replies
  • 0 Helpful votes

DUO EAM methods being ignored by Microsoft

We've been using DUO for years as the primary MFA for all clients.  Microsoft has repeatedly changed how we have to do this over the years, to the point where DUO is even deprecating the MS Azure Active Directory app soon because it hasn't worked pro...

Resolved! ISE Posture update issue

Hello mates,I’ve seen this error while trying to do a posture update: “Feed cannot be generated or parsed”:We have it for two weeks now and we patched our deployment yesterday but the issue is still here. When I try a to update now, I see my proxy go...

Image1.png
uRLKuzE by Level 2
  • 143 Views
  • 4 replies
  • 0 Helpful votes

ASA vs FDM vs FMC

I have a couple Firepower firewalls that run ASA image. Should I change the image to FTD? In that case should I use FMC or managing the FTD via FDM would be enough?As far as I know FMC provides more features that configuring an FTD via FDM, isn't it?...

Ab26 by Level 4
  • 113 Views
  • 2 replies
  • 0 Helpful votes

Route based VPN to Azure with BGP

I've been trying to setup a VPN tunnel between a FTD and Azure, but I am having some issues where one BGP neighbor is stuck in Idle/Connecting.I don't have any access to the Azure side. That part of the configuration is done by my custumer. Here is t...

Top Experts - Last 30 Days