Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Browse the Community

Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace

31751 Posts

Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.

70315 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3191 Posts

Activity in Security

Resolved! DMVPN issue with 800 series routers

I have a DMVPN network with 4331 hub routers. Our HQ in Memphis has a hub on AT&T, and another on Lumen. Our New York hub is also a Lumen connection. All are 500Mb up/down. We have about 35 spokes around the US that peer to all 3 routers. BGP is the ...

Cannot add FTD to FMC after deleting it from FMC

Hi,FTD was added and to FMC and while configuring HA in FMC, deleted FTD from FMC.While trying to add again to same FMC, both primary and secondary FTD not getting registered in FMC.Could you please help on getting the FTD registered with FMC.

riyas_tvm by Level 1
  • 91 Views
  • 5 replies
  • 0 Helpful votes

Windows Logon Excessive 2FA Challenges

Just recently, our Windows Logon duo integration has been challenging users for 2FA every time they log in, even if it's just unlocking a session they just locked. We've changed no policies in DUO or GPO. Thinking it was maybe a software version thin...

mattford by Level 1
  • 164 Views
  • 5 replies
  • 0 Helpful votes

Umbrella Redundancy for AD Connector

What is best practice when it comes to AD connector(s)?If we were to have TWO AD connectors, is there a way to have it only fail over to the other connector if the active one went down? Rather than adding an additional connector on a separate server ...

bnuxoll by Level 1
  • 41 Views
  • 1 replies
  • 0 Helpful votes

Query regarding BGP convergence on FTD HA pair

Hi, I'm looking at deploying BGP on an FTD Active/Standby HA pair (FTDs are 4215 hardware running 7.2) to enable routes to be controlled by neighbouring routers rather than relying on 100s of static routes on the FTDs. I was wondering if anyone could...

gavinhook by Level 1
  • 64 Views
  • 2 replies
  • 0 Helpful votes

SSH OVER HTTP PROXY WSA

Hello,A client is trying to SSH through the HTTP proxy (WSA), it works but the response times are huge.ssh_args = -C -o "ProxyCommand=nc -X connect -x proxy-http:8080 %h %p"It serves its purpose. HTTP proxy isn't designed for that, but has anyone tri...

cisco.13 by Level 1
  • 150 Views
  • 5 replies
  • 0 Helpful votes

Disable SIP ALG on Firepower 1010 by Web or Telenet

Hey allI have a Firepower 1010, I need to disable the SIP ALG on it, I have access to the Web Client and Telenet access to make changes, can someone give me an easy way to make these changes, I don't have the ASA Software that could access with.

scsawyer by Level 1
  • 58 Views
  • 2 replies
  • 0 Helpful votes

AnyConnect Microsoft Teams & Skype Packet loss

Hi Guys,We're having some issues since deploying the AnyConnect VPN with users reporting poor call quality and packet loss on Microsoft Teams and over Skype both audio and video calls?Is there anything we can try or tweak on our ASA and AnyConnect se...

Resolved! Best way to integrate ASA/ISE/Azure AD for MFA?

I want my VPN users on a Cisco ASA to authenticate against ISE but use Azure AD for MFA on the backend. So far, it seems there are three ways to do this. My requirements are that I must use AnyConnect and ISE. Setup Azure AD as External Radius Server...

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Top Experts - Last 30 Days