cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
453
Views
5
Helpful
5
Replies

CSA 5.0 LOG

guest
Level 1
Level 1

Hi

I have production server which as CSA5.0 installed, I get this error message flagged on CSA. It is managed via MC 5.0.

attempted to accept a connection as a server on TCP port 445 from 10.9.2.3. The operation was denied.

Is there way to set this rule in policies and attach to group so that https is allowed and not blocked to this server.

THANKS

Muhammad

5 Replies 5

tsteger1
Level 8
Level 8

Hi Muhammad,

First, confirm you want to allow this server to share resources. 445 is Microsoft-DS (SMB shares), not HTTPS.

If so, either create a network address set and use it with a Network Access Control allow rule or add the IP address to an allow rule for TCP/445.

Tom

Thanks Tom,

Basically it is sql database replication and updates to other server.

Could you pls guide me step by step to create and allow this rule if possible.

kind regards,

muhammad

Hi Muhammad, use the Event Management Wizard on the alert and that should guide you through creating the rule.

It should create a NAC rule allowing 445 traffic to the app (listed in the alert) on the server and you can choose the addresses you want to allow.

Check the rule it creates to confirm it is not too broad in allowing 445 traffic as that is a popular attack vector.

Tom

Thanks Tom, just quick one, how can i push this rule to all the hosts. Do i have to reset the hosts from MC or each time CSA polls and get the new config.

thanks in advance,

muhammad

Just create the rule and make sure it is associated with the rule module/policy/group and the hosts will get it.

Review Cisco Networking products for a $25 gift card