Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
My purpose and therefore configuration are very simple, but somehow it does not work. Purpose: create ACL in 2960 to deny all traffic coming from 192.168.2.60 to 192.168.1.50 via the port GigabitEthernet1/0/10. It permits all other types of traffic. ...
Recently a particular DNS request is being dropped by the rule “MALWARE-OTHER dns request with long host name segment - possible data exfiltration attempt” and this is affecting our access to that external resource. We looked over that event packet i...
In the Access Control Policy, we have mainly 2 rules in order: rule #1: Name: whitelist certain connections; Source Network: 192.168.1.5; Dest Network: 10.10.0.5; Action: Allow ("Drop when Inline" disabled)rule #2: Name: threat inspection; Source Net...
We are receiving this event "EXPLOIT-KIT Gong Da exploit kit possible jar download (1:27706:3)" from Cisco Firepower IPS. We tried to find which file in our server is causing this event, and from the IPS Pack Text we found this: Packet Text ....l@.....
Hi Peter, Thanks for your advice. Your question really helped sort things out! Here is the physical connection:192.168.1.50 connected directly to Cisco 2960 GigabitEthernet1/0/10 --> Cisco Core Switch 3850 -->192.168.2.60 My purpose and configurat...
Thanks again Marvin. Unfortunately it somehow does not work even after applying "No Rules Active". When I test the connection from 192.168.1.5 to 10.10.0.5 by transferring malicious files between them, Access Control Policy #1 is somehow ignored, i...
Hi Marvin, Do you mind telling the steps because I looked around but couldn't find the right place. Policies>Access Control>Access Control Policy>(our customised policy with two rules that are Access Control Policy #1 and Access Control Policy #2 )...