Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect, Duo, Umbrella, Secure Access and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Browse the Community

Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace

33810 Posts

Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Ada...

72710 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3670 Posts

OpenDNS

Ask questions not covered by support articles and documentation.

3624 Posts

Activity in Security

VPN: Authentication Failed

Has anyone who are using Secure access, experience "Authentication Failed" upon logging in to Anyconnect VPN? The IDP I'm using is Entra ID and followed all the steps based on cisco secure access help documents. Upon checking to the logs in Entra, it...

ckeyy_0-1787560580916.png ckeyy_0-1787560789036.png
ckeyy by Level 1
  • 0 Views
  • 0 replies
  • 0 Helpful votes

ISE Posture and delayed start services

Hi guys,We are busy implementing AnyConnect with the ISE posture module. One of the requirements for posture is to ensure the SMS Agent Host services is running. Howerver, I found that this service is set to delayed start, and especially when PCs are...

CWA certification for Extreme WLC through ISE.

Hello.I am trying to register Extreme WLC with NAD through ISE and obtain CWA certification.To register the Extreme WLC as a NAD, I need to create a separate Network Device Profile, and I would like to know what aspects I need to check in relation to...

CCC3 by Level 5
  • 151 Views
  • 2 replies
  • 0 Helpful votes

dot1x switch to MAB

I configure 2 radius on the switch and when 1st radius dead then the client will authenticate to 2nd radius but this request use MAB and not dot1x. In my mind maybe the switch have short dot1.x timer so the authentication will switch to MAB even radi...

hs08 by VIP
  • 131 Views
  • 4 replies
  • 0 Helpful votes

Resolved! Testing local username

Hello,We have configured AAA authentication on our routers with RADIUS server authentication. As a backup option  a local user and enable secret password has been configured.So far RADIUS server is working fine so there was case to test the locally c...

Duo Desktop - Startup times

Hello, We have noticed Duo Desktop takes a long time to load at Windows startup. Assuming this is because it loads in the user (startup) context, which is the lowest priority. If people launch their browsers before Duo Desktop loads, they have issues...

doGlooPA by Level 3
  • 531 Views
  • 5 replies
  • 0 Helpful votes

Failure to recover during an IPsec switchover

Traffic from Server-1 to Server-3 is encrypted using a policy-based IPsec tunnel between Router-1 and Router-3.Router-1 and Router-2 are configured in a redundant setup and share the same VPN endpoint address.The system is configured so that when Rou...

CHISHIUNG_0-1786755390710.png
CHISHIUNG by Level 3
  • 687 Views
  • 21 replies
  • 1 Helpful votes

Site-To-Site VPN between Meraki MX and FTD Managed by FMC

Hi there, has anyone had any success setting up a site-to-site VPN between a Cisco FTD being managed by FMC and a Meraki MX device? For the life of me, I can't figure out how to get it to work. The configuration on both seems to match, but I'm unable...

Cole Riese by Frequent Visitor
  • 2505 Views
  • 3 replies
  • 0 Helpful votes

Upgrading ASA 5506-x

Hello,Having a problem while trying to upgrade an asa 5506-x.This is a factory reset device currently running 9.5.1 and trying to get to 9.16.4.25.I can get there, but after a reboot the boot image is gone and I have to manually add it and wr mem.wen...

dbabcock by Community Member
  • 1671 Views
  • 3 replies
  • 0 Helpful votes