Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,I just noticed some elephant flows under security-related connection events. Is this correct? We have elephant flow detection enable, but I am not sure if they should be classified as Security-related and not just normal connection events?Thanks/C...
Hi,
I am migrating an ASA firewall to FTD for a customer and one of the things that need to be migrated is a QoS policy that limits the bandwidth for a number of VLAN:s that’s behind the ASAs inside interface.
In the ASA the policy looks like th...
Hello,
I am trying to configure a QoS policy in FTD version 7.7 where I want to limit the bandwidth to10 Mbit/s both download and upload.
The policy works but I don’t seem to be able to match it to a specific source IP address. Instead, it effects t...
Hello,
I have some issue sending LDAP request from a FTD 1010 device managed by FMC to an AD server over a VPN tunnel.
I have already added the AD server as a Realm in the FMC and verify that the connection from the FMC to the AD Server works.
Also, ...
Hello,
Every time I use FMT, it seams like the tool automatically create interface groups which I don't want to use. I want to use interface zones and no interface groups. To remove the interface groups after a migration, I first need change all conf...
Thanks, so then I guess this is normal that those events get classified as security-related.Since this traffic is trusted I will bypass those elephant flows from the Snort inspection.
Thanks Marvin, I will speak with the customer, and I agree this is properly a better approach. We could then do shaping instead of policing, which would be less aggressive.
According to the customer the guest WiFi saturate his 1 Gbit/s Internet connection and he therefore want to make sure the WiFi guest not using more than 500 Mbit/s. He's been using the QoS policy sucessfully on the ASA before and whish to use the exa...
I've done simillair migrations in the past and you have two options. Either you can ask for a full backup of their FMC, but then you have to do a lot of cleaning afterwards to get rid of everything that doesn't belong to your firewall. What I have do...