07-08-2021 06:58 AM
hi,
one of our clients has a CSPC server 2.9 with an specific schedule for uploading and discovering data.
they followed the set of needed firewall-rules and opened only those on their network.
now while this CSPC server is up and running they see traffic towards Centos and content networks outside the traffic mentioned in the installation-guide.
is there anyone here who knows why and wheretoo this traffic is being sent? theirsecurity team requested me to explain all the traffic they now block on the firewall.
and additional: why is there a schedule if the server does upload quicker and more often too: where and how is this done/documented?
would help me support our end-user more:)
07-08-2021 07:27 AM
Hi Michele,
I will be looking into this. Will get back to you with an update.
Thanks & regards,
Devashish Bourai.
07-09-2021 02:10 PM
Hello,
The Traffic that is being sent and received is all done in the cisco server ,going from cspc to cisco backend to the portal.
it is being uploaded to cisco server that is upload.cisco.com/72.163.7.113 .
For the Schedule part, Upload is done on regular basis , it is quick but we can schedule the uploads to a certain time as well. That is why there is Scheduling, so that the customer can schedule the uploads according their requirements.
It is done and documented in both SNTC portal as well as CSPC.
Thanks & regards,
Devashish Bourai.
07-12-2021 03:32 AM
07-12-2021 10:04 AM
Hello,
There is no need to schedule a separate upload profile, It will upload the collected data to the server when the collection is done as there is an option to export in the collection profile.
For the destination related, these are the port uses in CSPC.
Attaching below the screenshots for your reference regarding the Schedule/ Uploads and for the Port uses in CSPC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide