Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect, Duo, Umbrella, Secure Access and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Browse the Community

Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace

33828 Posts

Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Ada...

72730 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3679 Posts

OpenDNS

Ask questions not covered by support articles and documentation.

3637 Posts

Activity in Security

ISE captive portal issue on client

Captive portal is not popping up on client automatically while connecting to guest SSID. But if we open browser enter neverssl.com then it redirects to captive portal and allow us to complete guest registration and sign on process. Also receiving cer...

rajs2206 by Frequent Visitor
  • 331 Views
  • 6 replies
  • 1 Helpful votes

Poc demostration

I need a poc for demostration proposite, please help me, need a meraki mx75, mr for ap and two switchs, for vlans, one for vlan data and video, other switch for data an control acces, the ap should be in three vlans with diferent ssid, thanks

ingelserv by Visitor
  • 45 Views
  • 3 replies
  • 0 Helpful votes

Disable 802.1x in the estate

Hi ,I was asked to disable 802.1X for a few specific ports, and all I had to do was under the switchport: remove access-session port control-auto command.But recently, there was an incident across the entire branch where users were not authenticated ...

FYI - On-prem ESAs need to get your updates done

Hey everyone,  CISA just added CVE-2026-76461, a severity 9.8 vuln to the Known Exploited list.  https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog fixed versions are listed in the Cisco doc here: h...

Duo Gateway Authentication Options

I am running an implementation of Duo on a Virtual Desktop Environment (VDI) that uses the Microsoft Desktop Gateway App to perform 2FA on a broker/session host. I understand there are only two options with this implementation: Duo Push, and Phone Ca...

akond by Community Member
  • 63 Views
  • 1 replies
  • 0 Helpful votes

When Route-Based IPsec SAs Expire

For an IPsec SA established via route-based IPsec, if traffic ceases on the standby router, does the SA get deleted when its lifetime (86,400 seconds) expires?Please let me know if there are any other conditions or timer values that trigger deletion....

CHISHIUNG by Level 4
  • 82 Views
  • 3 replies
  • 0 Helpful votes

Migrate deployment ISE - Procedure and CAs doubts

I need to migrate a Cisco ISE deployment consisting of 1 PAN, 1 SAN, and 3 PSNs, for a total of 5 nodes. The goal is to move all VMs from VMware to Nutanix.My migration plan is to first move the PSNs one by one, verifying that services are operating ...

SupportAC by Level 5
  • 254 Views
  • 9 replies
  • 0 Helpful votes

Secure Access Success Capsules | Video Series

Welcome to our Secure Access Success Capsules! This program includes content that facilitates an adoption plan, which can be utilized based on each company's needs and the stage of implementation you are in. It consists of on-demand content for revie...

zsoulios by Cisco Employee
  • 3319 Views
  • 4 replies
  • 4 Helpful votes

Cisco ISE cni-podman4 interface down

 receive this alarm from Monitor Platform for ISE Interface:As part of the analysis, I compared the behavior with the second Cisco ISE node, atollon (172.16.20.130). This node also has a cni-podman4 interface; however, it is in an UP/RUNNING state an...

FMC 7.6.5 remote backup failing

Hi,We have 5 FMC servers which have been upgraded recently from 7.4.2 to 7.6.5. I found out that since then the daily backup of the FMC server towards a Linux server (Ubuntu 20.04) is not working anymore. The firewalls are still running on version 7....

johnslegers by Community Member
  • 44 Views
  • 0 replies
  • 0 Helpful votes

ASA5545-X

Hi all,I'm a student doing home-lab practice with an ASA 5500-X / FirePOWER setup. Cisco has since removed these files from the download portal, so I can't verify them against the official checksum anymore.Could someone who downloaded these directly ...

sBence268 by Community Member
  • 203 Views
  • 4 replies
  • 0 Helpful votes

Unable to establish communication with route-based IPsec

For our IPsec connection, our site uses policy-based IPsec, while the remote site uses route-based IPsec.When I changed our site from policy-based to route-based, the router’s tunnel interface went up and the connection was encrypted, but the count o...

CHISHIUNG by Level 4
  • 254 Views
  • 9 replies
  • 0 Helpful votes