Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect, Duo, Umbrella, Secure Access and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Browse the Community

Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace

33026 Posts

Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.

71856 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3449 Posts

OpenDNS

Ask questions not covered by support articles and documentation.

3479 Posts

Activity in Security

VPN with Alias on FTD

Currently we have an ASA and use Secure Client 5.1.8.105 and two profiles using Alia that authenticate via 2FA. To get the correct profile, split tunnel or full tunnel a use tacks the alias on to the URL and then connects, authenticates full 2FA and ...

Changing timezone from EST to UTC in ISE 3.3 patch-4

Hi guys,I have a five nodes cluster ISE 3.3 patch-4:Node 1:  PAN & Primary MNTNode 2:  SAN & Secondary MNTNode 3, 4, 5:  PSNThese servers were built before I work here, and the engineer before me used EST time zone instead of UTC as recommended by Ci...

ZscalerSME by Community Member
  • 76 Views
  • 0 replies
  • 0 Helpful votes

FTD migration

I’m currently working with an FTD 2110 firewall running version 7.0.6, which is managed by an FMC 2500 also on version 7.0.6.2. I've been tasked with migrating the FTD to a different FMC.I came across this document outlining the migration process.- h...

Need Help with Cisco Firepower 1120

Problem: Firewall shows it is connected to the Internet, it can sees the gateway. But, we not getting any data through. What We've Tried:Set up static and dynamic NATs, both before and after Auto NAT rules.Used various zone objects and policies (netw...

qlee by Level 1
  • 154 Views
  • 2 replies
  • 0 Helpful votes

Cisco ASA 5525 Migration to FPR-1140

Hello,We have a pair of Cisco ASA 5525-X and would like to migrate them to Cisco FPR-1140's.I started the migration and ended up at this screen: My intention was to set up a virtual FMC but I am not sure what version would satisfy my ASA units.Furthe...

uadmin_0-1746462540400.png
uadmin by Level 1
  • 265 Views
  • 5 replies
  • 0 Helpful votes

Cisco Duo: Learn about Two-factor authentication playlist

Duo Security, now part of Cisco, offers custom branding options to enhance your user authentication experience. This feature allows organizations to align the Duo interface with their brand identity, ensuring a seamless and trustworthy user experienc...

Screenshot 2025-05-08 at 11.58.51 AM.png
kstavrop by Cisco Employee
  • 77 Views
  • 0 replies
  • 0 Helpful votes

Resolved! FTD 7.4.2.2-28 Site to Site VPN Flow is denied by configured rule

After an upgrade from FTD 7.4.2.1-30  to 7.4.2.2-28 a Site to Site VPN stopped working.This is a packet trace, external 194.13.185.2 ,  Internal 192.168.20.23It is strange, because all phases have result "ALLOW".Except for the final punch line:  Flow...

FGR by Level 1
  • 250 Views
  • 6 replies
  • 0 Helpful votes

IPSec DVTI /SVTI issue

Hello,We're in the process of setting up a HUB-and-SPOKE topology using IPsec VTIs.The HUB router is configured with DVTI, and the SPOKE router uses SVTI.While there is IP connectivity between the routers, Phase 1 of the IPsec negotiation is failing....

Soma-II by Level 1
  • 476 Views
  • 20 replies
  • 0 Helpful votes

TLS Metadata without decryption

Hello - can FTD/FMC running snort3 collect >TLS1.2 client hello/server cert metadata collection in connection events for example? I do not want to deploy EVE and SSL decrypt is not an option. I just want to capture server cert metadata, SNI etc. Is t...

JH8286 by Level 1
  • 104 Views
  • 2 replies
  • 0 Helpful votes

Where to get help for the FMC platform?

I am needing to open up a port that will go from outside to inside for TACACS authentication.  I have created what i beleive is the necessary NAT translation from an available public IP address that our provider has given us in a publicly routable bl...

KMNRuser by Level 1
  • 209 Views
  • 5 replies
  • 1 Helpful votes

Duo Active Directory User Sync fails sporadically

Hello,I started to notice that the Duo Active Directory User Sync is failing sporadically (from Automatic sync frequency jobs). The manual sync works fine and the next Automatic sync frequency ones work as well. The reason on the logs is " Sync cance...

amelo@ by Level 1
  • 139 Views
  • 3 replies
  • 0 Helpful votes