Firewalls Over TCP / IP Stack
Jun 25, 2011For protection of any network architecture,use of firewalls (either hardware or software) only at Network ,Transport and Application Layers of TCP/IP stack. Why not at remaining layers?
View 1 RepliesFor protection of any network architecture,use of firewalls (either hardware or software) only at Network ,Transport and Application Layers of TCP/IP stack. Why not at remaining layers?
View 1 RepliesI have a customer with active/standby on a pair of 5510's with the CSC modules. They were inquiring about the AIP/ASA, and since this would NOT work in their current setup, would getting a pair of 5510/AIP configured for transparent failover work placed in front fo the existing units? Would I need to have a switch placed between the AIP and CSC ASA's? Or would I setup the ASA's for context based Active/Active failover to interconnect the ASA's to the existing units, but I still see a need for a switch.
View 1 Replies View RelatedIs there a stacking cable that is "bent"?Im using this cable:"CAB-STACK-50CM", "Cisco StackWise 50CM Stacking Cable".But it takes up to much room in the back of the switch, is there such a thing as "bent" stacking cable.
View 1 Replies View RelatedI have 3 switches in my 3750 X stack. I am getting the following error in the logs: %PLATFORM_STACKPOWER-4-PRIO_CONFLICT: Switch 1's power stack has conflicting power priorities. Not sure what I should do next. Below is my Stack-power configuration:
Power stack name: Powerstack-1 Stack mode: Power sharing Stack topology: Ring Switch 1: Power budget: 735 Low port priority value: 20 High port priority value: 10 Switch priority value: 2 Port 1 status: Connected Port 2 status: Connected Neighbor on port 1: c464.1308.7900 Neighbor on port 2: e8b7.4827.e680
Switch 3: Power budget: 729 Low port priority value: 22 High port priority value: 13 Switch priority value: 4 Port 1 status: Connected Port 2 status: Connected Neighbor on port 1: 2894.0fd9.9f00 Neighbor on port 2: 2894.0fd8.e200
Switch 2: Power budget: 690 Low port priority value: 21 High port priority value: 12 Switch priority value: 3 Port 1 status: Connected Port 2 status: Connected Neighbor on port 1: 2894.0fd8.e200 Neighbor on port 2: c464.1308.7900
Each switch has its own 715W power supply in it and all check out OK.
A site that i am responsible for has the following equipment installed:
2 x 3750G Switches configured as a stack using Stackwise - Collapsed Core/Distribution Layer
5 x 2960G Switches as Access Layer switches
WAN connections into the Core/Distribution Layer are all Gigabit Ethernet over Fibre.This is a dedicated CCTV Network with 50 Cameras all streaming video into the Core (decoders connected to access switches)Each 2960G has 2 links to the Core/Distribution 3750G Switches, 1 to each switch - Gigabit.I'm running rapid-pvst on all switches, so spanning tree is blocking one of the ports and effectively halving the 2 gig bandwidth. Next year our customer is going to add in a further 50 - 60 cameras.After monitoring the current loading on the ports in use, we have suggested to the customer that the 2 connections to each should be Ether-channeled together. [code]
First interface takes commands no problem, keep getting the message that etherchannel cannot be configured across different switches in a stack when i try to put the second interface commands on.
We currently have as our stack master a 24 port Non-PoE that we want to replace with a 48 port Non-PoE. The 48 port switch at one time was provisioned as switch 3 in the stack (not the master). Correct me if I am wrong, but theoretically all I should need to do to get this working is to shut off the existing master so it re-elects a master and then provision the 48 port switch as the new switch one and make sure switch 1 has a high priority?
Do I need to write erase the switch that is replacing the current master first?
I have a cisco 3750v2-48TS connected to a cisco 3750v2-48PS in a stack. The stack ports show up as down/down in the stack.Is there a limitation as to if they can be connected.? I mean can we have a PoE and a non PoE in the stack?
View 1 Replies View RelatedI opened my iTunes program today and noticed a roommate's MP3 files were picked up on my network. I think the name of the program is Rocket Tube MP3. Anyway, I came on here because our computers use a Wi-Fi internet connection and I was wondering how much of my web activity (history, cookies, temporary files, etc) he could see from my laptop if his computer was a desktop downstairs. He's very tech-savvy (a former IT guy) and I don't want him snooping through my personal records.
View 2 Replies View RelatedI have a problem discovering some ASA firewalls on a network. I have several ASA firewalls on this /24 network, but some of them I can't discover e.g 149.x.x.107 is discovered ok, but 149.x.x.20 I can't discover. It seems that it's not even trying to discover the devices I have problems with. Nothing is shown in the discovery log.
View 11 Replies View RelatedAm I able to legally download and upgrade software versions still on ASA firewalls?I have not had an issue in the past as this has not effected the license.I cant find anything online saying that you cant due to Cisco's new Software license policy changes.
View 1 Replies View RelatedWe are a non-profit organization that is heavily reliant on interns that use their own laptops a lot here. My concern is they come in and connect to our wireless network with no supervision or anything else. I am worried they will introduce a virus, trojan, or something to our network. What the best way to keep them from introducing unwanted malware from a thumb drive, virus in email, or something to that effect shy of standing over them while they install and run an antivirus software?
View 7 Replies View RelatedI have problem with the Lan-to-Lan VPN tunnel.the VPN working fines since 9 months ago without any problems.Suddenly got the problem!,In last two days we faced problem the VPN down.in first time the problem in phase-2.. but after that in phase-1... in latest no data packet received to their side.
View 1 Replies View RelatedI am looking for some resources on what steps would be involved in configuring a Cisco ASA 5500 when obtaining a new ISP. Since our static IP will be changing with the new ISP, just need to know what configurations changes will need to take place. We currently have a working config with DSL, but are switching to cable. We are using a DMZ configuration, and are going to try using ASDM first since that should be easier
View 3 Replies View RelatedThere are three Win 7 laptops on the LAN trying to connect to the ASA5500 Firewall. They generate a Severity Level 3 alert and try the same port three times then move to the next numerical port and try that three times. Is this a malicious Hack.
View 5 Replies View Relatedcan i change my nat type from type 3 to type 1
View 19 Replies View RelatedI have been trying to get into one website (url)The world's best online marketplace, List free Classifieds,buy and sell - auction,post a job and get hire from over 1 million top professionals. | Wanaifieds.com and I can't get into the site from my home I can get into the site everywhere else but here I called the service provider and their telling me it's not them they don't block website and the IP is not stationary so their nothing wrong with their end I called the hosting company of the website and they told me they don't block any IP's I don't know what to do I do remember when it was working about 4 days ago I tried something o the site and I messed up and I clicked back instead of putting my password a little box poped up and said something about a certificate or something but I just clicked off and when I tried to get back on the site.
View 6 Replies View RelatedI'm working with Cisco ASDM 6.1 for pix. I want some of ip addresses are not shunned thus provide a list of addresses which should not be shunned in threat detection, but some of ip addresses are shunned yet.
View 1 Replies View RelatedI want to block 10.0.0.1 and 192.168.1.1 but my router says invalid domain so if will the guess network be able to go to page 10.0.0.1 and 192.168.1.1 even though I don't block it? I have a bypass account but don't want anyone else to access 10.0.0.1 and 192.168.1.1. Also can you tell me some proxy sites I can block?
View 11 Replies View RelatedWindows firewall settings cannot be displayed because the associated service is not running
View 4 Replies View RelatedI'm not sure how I turn off my firewall
View 4 Replies View RelatedFinding the difference nms and SIEM. But I couldn't find until now.
View 3 Replies View Relatedwhen I run nestat -b command. I always see a lan ip sending TCP traffic to my computer with state syn_receivedProto >> Lan Address >> Foreign Address >> state >> Process idTCP >> (my ip) >> 192.168.2.222(lan ip) >> syn_received >> 4
View 6 Replies View Related'm trying to set up a vpn connection through two ASA 5510 firewalls.My network is as follows:
PC | FW A | Internet |FW B| - lan |
I am trying to achieve the following:
PC | FW A | Internet |FW B| - | DMZ | - | FW C| - | lan |
However, I am not sure where the VPNs will need to terminate and how I will achieve this taking into account the WAN IPs.
How many of you use GNS3 for ASA 5500 Firewalls along with ASDM? While I am on the subject of GNS3 I had a questions about the new version and the capture feature. I installed the latest version last night with the new live capture features but it seems to be only one way capture. T Is there a way to fix this?
View 3 Replies View RelatedI am trying to setup a Cisco ACS 5.2 for both login and enable authentication to asa 5505s, 5510s, and catalyst switches. I am testing with an ASA 5505. The initial authentication to the firewall works, but when I try to enter privileged exec mode using the enable command, it doesn't work. I have the user setup on the ACS with a password and an enable password and privilege level 15, I have the device setup on the ACS, I have the tacacs+ server setup on the firewall and pointed to the correct server address, and the AAA commands for telnet, ssh, and enable.
View 9 Replies View RelatedMy Iphone 4s will no longer connect to my WRT54G Linksys router. I know it's a security issue because if I disable security, then it connects. I'm using WPA-Personal, AES, Mixed mode.I've already tried resetting the network settinegs on the iphone a couple of times.
View 3 Replies View RelatedI've recently spotted my router's configuration page is shown publicly if they connect to external ip or a domain name I've set up to my own IP through a web browser (it's a game server)I see it as a security thread, that everybody can connect to my router's configuration page and want that down asap!
View 3 Replies View Relatedgood web monitoring/filtering software for use in the home? I want to be able to monitor/review visited websites and block harmful/unsuitable content.
Must be compatible with Mozilla Firefox.
I am trying to figure out how to give computers that connect to my LAN limited access. I have heard that some viruses, though rare, may travel through the network and infect all computers on the network. I want to prevent this. Is there any way to give computers connected to my network strict access to only the internet to prevent viruses or any other harmful attacks?
View 1 Replies View RelatedA couple hours ago I installed AVG free antivirus and pc-cleanup and decided to uninstall them after seeing poor results. When I rebooted my computer, I was unable to, and still am, to find any wireless networks. I've tried disabling Microsoft firewall and restoring but everything has failed.
View 15 Replies View RelatedDoes any one know of a good parental software, one that controls searches and websites. I just bought my 12 yr old daughter a laptop and want to keep her safe online
View 6 Replies View RelatedI have ran speed tests using speedtest.net whilst having my kaspersky internet security 2011 both enabled and disabled.With it enabled, i get download speeds of around 3MbpsWith it disabled, i get download speeds of around 12Mbps3Mbps is awful and loading webpages can take a long time sometimes. What can be done to resolve this problem?
View 3 Replies View RelatedI have a sonicwall tz-170 that has a standard interface. It is the main system with IP 192.168.1.1.Another location using IPs 192.168.0.1 has a dvr (192.168.0.154) with ports 80, 37777 and 37778.I can access them from the main location just fine but setting up a service then a rule does not allow me to connect from outside the network. I assume this is the same for anything trying to reach the other side of the vpn but I'm not sure
View 3 Replies View Related