Security

Explore the security forums and share your expertise about firewalls, email and web security, Identity Service Engine, VPN, AnyConnect and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Browse the Community

Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace

31769 Posts

Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.

70352 Posts

Duo Security

Get started with or get better at administering and using Duo by interacting with peers and experts!

3194 Posts

Activity in Security

ISE CoA Reauth for Aruba 2530

Hello everyone, Does anyone know the attributes to configure to make the CoA type reauth work on an Aruba 2530 switch (16.11)? I managed to make the CoA Disconnect and port bounce working but I don't have the solution for reauth and I need it for pro...

PXGrid 2.0 High Availability - Primary Pan Outage

I have an EVE-NG lab that consists of a Panorama, 1 FW, and 4 ISE nodes (see lab.jpg attached).  The Lab ISE nodes are running 3.2 patch 5 and panorama and Firewall is running 10.2.7-h3.  In reading the 3.2 and 3.1 admin guides they both state in the...

ryanbess by Level 1
  • 93 Views
  • 1 replies
  • 0 Helpful votes

Renewall of Admin Certificate

I have to renew the admin certificate in a pair of ISE nodes (Prim / Sec) on Version 3.2.0.542 Patch 4. Currently both devices have the same admin cert that expires in little over 3 weeks. All the names and IPs in this thread are placeholders. I gene...

Sergio C by Level 1
  • 243 Views
  • 11 replies
  • 0 Helpful votes

unknown IPs in FTD outbound logs

I am managing FTD-1120s with FMCv both running v7.2.1 software.  In my ACP I have a GEO rule to block all outbound traffic to China, Russia, and I few other "hotspots".   When I search for events that match this rule, most of the traffic is from inte...

tato386 by Level 6
  • 131 Views
  • 1 replies
  • 1 Helpful votes

CiscoISE policy applying on switch problem

Hello,I have a problem with applying policies from CiscoISE 3.2 on switch C3750. It simply doesn't stop the unauthenticated users from logging in to switch, nor it prevent commands that are forbidden by the created policy. In Live Logs I can see that...

Screenshot 2024-04-22 at 08-57-04 Identity Services Engine.png
mitros by Level 1
  • 321 Views
  • 17 replies
  • 0 Helpful votes

Trustsec Network Authorization not Working

Hi All,I am newly building trustsec in my environment,trying to add one of the switch under trustsec. Have configured Trustsec settings and COA on the ISE for the switch and added the appropriate aaa commands , radius servers and cts commands.But sti...

About Errors When Connecting to [anyconnect VPN]

The following message is displayed when the connection button is pressed. Please tell me how to solve it. Certificate Validation Failure   AnyConnect VPI version 5.0.04232 Secure Client UI version 5.0.00889 Certificate Expiration Date 2025/4/3    

Translator by Community Manager
  • 42 Views
  • 0 replies
  • 0 Helpful votes

Resolved! Cisco FMC integration with TG 5004 and AMPv Private Cloud

Hello Experts,   I have a Cisco FMC with managed Device AMP 8130 Appliance with on-premises Threat Grid and Private Cloud. I got issues about the Integration part of the FMC with TG and FMC with Private Cloud and also having trouble with TG to Privat...

Cisco ESA - SMTP authentication best practice

Hello community,  what is the best practice to use SMTP authentication ? If we have smtp authentication on mail server is it a good practice to switch it to Cisco ESA ? I can`t find, what is the mail flow when user is using smtp authentication on Cis...

Duo Desktop not recognized

Hello, I am using Cisco Anyconnect to connect to VPN. The system is using Duo Desktop for device health. It is already installed, running and all the checks are ok. However, I am getting this error message and not able to proceed: Install Duo Desktop...

Sh2024 by Level 1
  • 52 Views
  • 0 replies
  • 0 Helpful votes

Secure Firewall Migration Tool - Login Issue?

Hi,  Does anyone know if we need something special on our CCO account in order to use the Secure Firewall Migration Tool? I have installed it, and as soon as I run it, it opens a browser and asks me to authenticate. Afterwards, I got a message saying...

StealthWatch SSL/TLS Client Identity Certificate

Uploaded the Trusted CA Root certificate to the "Trust Store" in the SMC. Then I generated a CSR from the SMC "Additional SSL/TLS Client Identities" and signed it by the CA server "Windows server", but when I upload the new signed certificate and cli...

Adam99_Security_0-1712294473439.png Adam99_Security_1-1712294535819.png

Cisco Firepower 2130 Site to Site VPN Connection to AWS

Hello,   Good Day, Seeking help from you guys, currently I`m configuring Site to Site VPN connection from Cisco Firepower 2130 to AWS. I`m using the download configuration from AWS which is Cisco ASA 5500 9.X file, and I`m using Cisco Firepower 2130 ...

Top Experts - Last 30 Days