Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
If I create an event set that for example filters to only file access control denied, only in the music download prevention policy and I choose view I see just that, all denied file access control events from the music download prevention policy.I na...
I uninstalled Ciscoworks and Management Console for security agents. After reinstalling eveything the whole VMS product is super slow. Everything works fine but it takes me about 10 minutes to even log in to Cisco Works and then another 2-6 minutes...
OK, my client is using Patchlink to roll out patches. The patches seem to be downloaded to C:\windows\temp\XXXXX.XXXThe trojan detection rule kicks off the following every time:The program 'C:\WINDOWS\Temp\IE6.0sp1-KB889293-Windows-2000-XP-x86-ENU.e...
Patch link is being run in my CSA environment. My current CSA clients generate 1000's of "potential worm propagation" error messages per day. Cisco has told me that since there is no way to configure the worm rule untill next version I basically ha...
I am having a problem after installing the csa agent and doing an auto reboot. After the first reboot the novell login script fails to connect to all of the drives and the workstation takes forever to finish rebooting. After that first reboot the n...
Thanks for the suggestions. The problem was the test network I had it on. If you move servers make sure you do the new MC on a live network or at least a test network with a live gateway somewhere. If the 2000 server can't connect to the default g...
I have been doing some testing with this setup today. It seems to me that the dynamic application class doesn't always clear out after the 10 second threshhold or whatever time you set on it.After you are allowed to freely download the xls off the m...
Thanks, I had got it. I thought that I had already gotten the culprit downloader (gravitx.exe) in that rule but I got app classes confused. What was weird to me is the fact that the event wizard was able to generate a completely useless rule. Kinda...
TESTMODE:Potential worm propagation: The process 'C:\Program Files\PatchLink\Update Agent\dagent.exe' (as user NT AUTHORITY\SYSTEM) has read downloaded content (file Scripting.FileSystemObject) and is accessing an email or network related resource (A...