Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi, I have enabled Netconf on IOS XE device 16.9.4 using 'netconf-yang' and 'netconf-yang feature candidate-datastore'. I am using Advanced Netconf Explorer and Yang Explorer tools for testing purposes. Get RPC's are working as expected to amend the ...
Apology for the basic question, I am enabling Netconf on XR & XE platform but I am bit worried about security aspect of the Netconf so trying to grant least privilege access to the client. When configuring CoPP or any other way to restrict specific I...
Hi, Apology for the basic question, I am enabling Netconf on XR & XE platform but I am bit worried about security aspect of the Netconf so trying to grant least privilege access to the client. When configuring CoPP on Cisco Device, under control-plan...
Hello, Please could someone please suggests me a equivalent command list BGP prefixes advertised using Router Target (on a PE router running IOS XR. #sho ip bgp vpnv4 vrf vpn1 ?community Display routes matching the communitiescommunity-list Display ...
Hi, I was wondering if it is possible to block / deny SNMP SET packets passing through Cisco ASA firewalls as well as targeted to Cisco ASA firewall but allow SNMP Get and Trap from specific host within a network? ThanksRT
Hi Seb, Thank you for the prompt response. As I have no control on the SNMP Server so I am unable to enforce SNMP policy. As per security requirements I wanted to secure the network where I must only permit SNMP Get and Traps but deny SNMP Set throu...
Thank you for your response RJI and Rahul. I did think of VPN filter but not attempted it.Let me explain i need two tunnels between the same pairs of ASAs using different tunnel endpoint IPs but having the same encryption domain in my example;Site A ...
Hi Florin,
Thank you for your suggestion but my issues is focused on support for cached certificate or HASH_AND_URL which is documented under RFC 5996.
RT