Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I use FTD 6.5 managed by FDM. I use Access Control rules with user information from AD active identity. Authentication works well, but I have problem when there are users changes on PCs. When new users login to PC, user session on FTD remain from pre...
I have ASA with Firepower module controled by Firepower Management Center. ASA protect some network segments from other WAN. I have enabled signature PSNG_TCP_PORTSCAN and PSNG_TCP_PORTSWEEP. Portscan Detection Sensitivity Level is Low (or Medium).I ...
You are right
But "outside" for me is a global corporate network with a large number of legitimate users who connect to servers on LAN network. One client can establish up to 20 connections to 10 servers simultaneously. And such behavior is consid...
Can you explain me what do "Watch IP" field? By documentation: "If you want to monitor specific hosts for signs of portscan activity, enter the host IP address in the Watch IP field", but by default all host (whitch hit in Access control rule with In...