Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Browse the Community

Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace

31750 Posts

Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.

70312 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3191 Posts

Activity in Security

Secure Client ISE 3.2 Posture failure

I have just started using Secure Client Posture on my windows workstations.  All but 2 work fine.  The two are using the IP of the ISE instead of the FQDN.  All systems have the same ISEPostureCFG.xml files on them. If I disable the network connectio...

SSH OVER HTTP PROXY WSA

Hello,A client is trying to SSH through the HTTP proxy (WSA), it works but the response times are huge.ssh_args = -C -o "ProxyCommand=nc -X connect -x proxy-http:8080 %h %p"It serves its purpose. HTTP proxy isn't designed for that, but has anyone tri...

cisco.13 by Level 1
  • 135 Views
  • 4 replies
  • 0 Helpful votes

IPSec VPN Tunnel Lan-to-Lan decrypt count zero

Hi, I have one issue with IPSec tunnel Lan-to-Lan between ASA 5525x (v9.8) and ASA FPR 2110 (v9.16). My Tunnel is up but ping between each client was not successful. Both peer status sh cry isakmp sa in "MM_ACTIVE".I ran packet-tracer icmp between pe...

El Rondo by Level 1
  • 237 Views
  • 15 replies
  • 0 Helpful votes

ISE 3.2 Repeat Count Details

Hi,on ISE 2.4 in the live logs pages the report that one got clicking on the repeat counter was very useful because the endpoints were sorted by repeat counters. So it was very easy to find the endpoints with high repeated counters.With ISE 3.2 the r...

Cannot add FTD to FMC after deleting it from FMC

Hi,FTD was added and to FMC and while configuring HA in FMC, deleted FTD from FMC.While trying to add again to same FMC, both primary and secondary FTD not getting registered in FMC.Could you please help on getting the FTD registered with FMC.

riyas_tvm by Level 1
  • 73 Views
  • 4 replies
  • 0 Helpful votes

Snort3 not recognising SMTP/S but Snort2 did/does !?

I'm in the process of updating all our FTD's from Snort2 to Snort3 & almost everything appears to work, except SMTP/S email.Under Snort2 it shows in event logs as SMTP/S Client traffic type correctly, but when Snort3 is enabled, it does not recognise...

ida71 by Level 1
  • 116 Views
  • 5 replies
  • 0 Helpful votes

AnyConnect Microsoft Teams & Skype Packet loss

Hi Guys,We're having some issues since deploying the AnyConnect VPN with users reporting poor call quality and packet loss on Microsoft Teams and over Skype both audio and video calls?Is there anything we can try or tweak on our ASA and AnyConnect se...

ISE Cert Question

HiDo I need to generate a CSR for a cert on ISE its a *cert or can I just add the cert to the ISE Nodes for Portal use.?? Thanks

PKCS12 (PFX) without a supplied password error

We have clients receiving a "PKCS12 (PFX) without a supplied password" error while connecting to RAVPN using Cisco Secure Client (5.1.2.42). The headend device is FTD 3130.The full error is "There was an erro during initialization: PKCS12 (PFX) witho...

Issue after Uninstalling Anyconnect

Anyconnect has been uninstalled on my Mac. I have been having issues with network connections so I ran "systemextensionsctl list" in Terminal. When uninstalling anyconnect it looks like the "com.cisco.anyconnect.macos.acsockext" Socket Filter Extensi...

jjnorris2 by Level 1
  • 139 Views
  • 3 replies
  • 0 Helpful votes

Resolved! Can FMC running in vsphere be migrated to AWS?

I plan to migrate a FMC running in vsphere to AWS. Initially I plan to: 1. Build the FMC in AWS as brand new; 2. Backup the existing FMC (running v7 already) and then restore the backup in AWS FMC; 3. Login to AWS FMC serial console to change the MGM...

m1xed0s by Spotlight
  • 4597 Views
  • 22 replies
  • 0 Helpful votes

SSL VPN Encryption Type/s?

Hello,When configuring SSL VPN, the default encryption type is "ssl server-version tlsv1.2 dtlsv1.2", which only shows up with a "show run all". In that output, I can also see that "ssl cipher tlsv1.2 medium" and "ssl cipher dtlsv1.2 medium" are disp...

FIPS_Venn_Digram.png

Cisco Secure Client XML overwrite issue

Hello, any help appreciated.I am having issues when trying to assign a different group policy to a user where the group policy contains a different client profile (XML) to the one used to connect in the first instance. This is what I am trying to do....

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Top Experts - Last 30 Days