Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Trying to map a drive from Hub Server to Management Site Server. Hub site is protected by a FTD 2130, when I try and map the drive I am getting denied by a Snort Drop (Rule ID 268434432). The users kept trying to connect an eventually it looks like...
Have two HA clustered FTD2130's managed by FMC and I am unable to upgrade the FTD's past 7.2.1FMC currently running 7.3.1.1FTD's running 7.2.1...trying to get them up to 7.3.1; All policies on the FTD's are up to date.FTD's working normally in a HA c...
Physical vs Virtual design issue that I'm looking for feedback on, I have a WAN architecture that links outlying user sites back to a core site via Ethernet Private line service. Three sites connected via three "ethernet" links. I then layer a VTI ...
Trying to setup an email alert when a FTD loses connectivity with a TCP based syslog server. Setup is several FTD2100's managed by a FMC. Devices-->Platform Settings:SMTP Server: mail-server-objectSyslog-->Logging Destinations: Email (Use Event Lis...
Looking for some assistance...running into some odd behavior with authenticated NTPNTP synchronization always fails when authenticatedSource: Cisco 4451 and 4331 routers are NTP sources (Running IOS XE 17.6 code)…pulling from public NTP (sync'd strat...
Pulled the prefilter, and ran the debug. Not seeing any SID/GID....simply kicks it down to rule 180 which the default action Block rule. Its almost acting like it kicks the packet to snort...snort see's its already black listed and kicks the packet...
Here is the redacted ACL list with entries that match the packet trace...on a side note since my Systems team was complaining I modified the prefilter rule for this traffic flow to bypass inspection for this specific flow and that worked like a charm...
That might be difficult....there are a ton of rules and I need to vet the export though our security office so they can redact any verbiage they dont want going out. I can more easily pull any rules that are specified in the packet trace if that wou...
Ok...I see the rule ID's are actual numbers for the ACL Policy lines. I got into CLI and went into the /var/sf/detection_engine/xxxxx/folders and looked at the ngfw.rules file and the ruleid: 268434432 corresponds to the deny any any rule at the end...