Is there anything wrong (or missing) with the sample TACACS config below? And does it matter what order the commands are entered? In config docs, I've seen so many variations of tacacs config that it's making my head spin so I'm trying to make sense ...
Assuming you're using FMC, how would you exclude a given IP address from a specific IPS alert? For example, system traffic was blocked due to a specific malware definition but it was determined that the traffic was legitimate and you only want to ex...
Is there anyway to create report on devices in FMC? We have hundreds of devices and I'd like to create a report showing basic info such as device list, model, code rev, etc. I do not see any way to do this?
App owner complained of blocked traffic. I verified firewall rule was correct and traffic was allowed. I then searched Intrusion events and found that the traffic in question is being dropped by "NETBIOS DCERPC possible wmi remote process launch"
...
When I'm on a webex conference call as a participant, I frequently need to mute / unmute. When I do this I hear a beep on my side. Do other participants also hear a beep every time I mute / unmute?Thanks!
@SiliconBrian are you sure about the need to remove secondary IP before adding it as primary? I lab'd it up in EVE-NG and was able to apply the secondary as primary in one command. Running - ip address 10.10.10.1 255.255.255.0, made it primary and r...
Thanks Marvin, that was very helpful! One final question, the alert was triggered by a single host behind a single SFR. The current access control policy targets 100+ devices. Is it cleaner to copy/rename both the current IPS and Access Control Po...
Thanks guys, is this documented anywhere? I see where you're heading, but not sure of the steps to create new IPS policy to be used in access control rule.
My scenario is this > "If the purpose is to disable only a specific Snort rule (s) for a sp...