Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect, Duo, Umbrella, Secure Access and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

watch here Journey banner_2

Browse the Community

Network Access Control

Cisco Identity Services Engine (ISE), Cisco Access Manager (CAM), Zero Trust Workplace

33563 Posts

Network Security

Engage with peers and experts on network security topics such as Secure Firewall Threat Defense, Ada...

72406 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3566 Posts

OpenDNS

Ask questions not covered by support articles and documentation.

3530 Posts

Activity in Security

locked out from duo administrator's account

Hello,I'm the administrator of our duo security but the phone with my duo mobile is broken.I have a new phone but since the old is not working I cannot transfer the account.I'm also locked out from all protected devices.How can I login to administrat...

zpj61 by Community Member
  • 30 Views
  • 1 replies
  • 0 Helpful votes

unravelling FTD DNS settings and configuration

 I currently have an FTD that has public DNS configured on the management interface (>show network, >show DNS system have Umbrella IPs).  I have internal DNS IPs assigned to inside data interface using the platform policy.  I did not check enable DNS...

tato386 by Level 6
  • 423 Views
  • 7 replies
  • 0 Helpful votes

auto ugrade to secure client version 5.1.14.145

Dear Com ...Upgrades during Start-Before-Login (SBL) appear to occur twice and customization does not occur during initial upgrade. Also, a message box is'nt shown that states: "The installation was successful. Changes will not be effective until the...

rstockum by Level 1
  • 124 Views
  • 2 replies
  • 0 Helpful votes

Cert Authentication Profile in ISE

Hello Greg,  If I want to use below condition of cert like Common Name and OU what will be CAP Auth Profile config ? Specially Use Identity From Field in CAP ? I think I should only use Subject ? which will cover CN , OU.  @Greg Gibbs 

MSJ1_0-1768937761722.png
MSJ1 by Level 1
  • 147 Views
  • 2 replies
  • 0 Helpful votes

NAC using Hybrid Joined Devices with Entra and On Prem

Hello Greg, @Greg Gibbs  If User Device is Entra Joined and Users are Entra Joined and AD Joined in other words Hybrid is this use case is tested with ISE ? Is there a reference document you can share ? If users are Hybrid joined can we still do NAC ...

MSJ1 by Level 1
  • 322 Views
  • 3 replies
  • 0 Helpful votes

Resolved! DUO - allow logon locally

Hi, We are using DUO Wondows logon 3.1.1 to enable MFA for our Jump servers. Is it necessary that, users who need to authenticate to those Jump servers should be under the GPO policy “Allow logon locally”. we have around 500 users who need access to ...

gandlal by Level 1
  • 2715 Views
  • 5 replies
  • 0 Helpful votes

URL Filtering on FMCv on CML LABS

I have setup up a number of FTDS that are managed by FMC in CML labs. I have setup the in-built desktop in CML that is hanging off a FTD. I am able to get the internet via FTD-->Router (NAT)-->External Connector and I am able to get internet access f...

IPNINJA by Level 1
  • 1655 Views
  • 10 replies
  • 0 Helpful votes

Port-channel between FTD and ASR 920

We are having issues establishing a port-channel between an FTD 3110 and ASR 920. FTD LACP mode is set to "Active" while the ASR is set to "Passive". But it doesn't work.However, we have seen the FTD 4110 with an LACP mode of "On" and ASR "Passive" w...

Slowness after using ECMP

We have a 3110 with version 7.6 managed by FMC 7.6. The flow is User >> WLC >> Core Switch >> Cisco FTD >> Internet Switch >> ISP Router 1 & ISP Router 2. On FTD we have created sub-interfaces of 10 Gig link and we have two 1 Gig links from ISP. We a...

sahdogra by Level 1
  • 246 Views
  • 3 replies
  • 0 Helpful votes