collapse

Search


User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Recent Posts

Pages: 1 2 [3] 4 5 ... 10
21
If I understand correctly, you are trying to do client cert auth on a VPN but because the machine is not domain computer, it does not have a cert and you are trying to generate a cert separately and import it to the computer but then it fails authentication. Is that correct? Have you done any debug on the FTD to see why authentication fails? Also, client cert should be installed under Personal > Cert folder and not Trusted Root Cert. May be AnyConnect client couldn't locate the cert?
22
I generated an Enterprise CA on my domain (secops), and I'm trying to generate an identity cert for a client network so we can use Duo with FMC/FTD. Everything is working from "MY" domain joined computer (following the Microsoft/ISE export/CSR process), I have my ACC-ROOT-CA, pasted the contents into the FTD > Add Cert Enrollment > CA Certificate|Manual page, generated CSR, took the contents and back to the CA server to sign the cert, getting the .cer with my client's certificate information (O=IT, etc). My client gets an authentication server failed and so do I from any non-domain joined computer. How do we create a cert such that any computer with that cert stored in the Trusted Root Cert Authority can pass authentication? Once that is resolved, it will all work b/t Duo SSO and RAVPN with FTD!
23
Security / Re: Migrate IPS rules for FMC 6.4 to FMC 7
« Last post by spykas on April 22, 2022, 04:55:07 AM »
Yes , that is the case .

Thank you.
24
Security / Re: Migrate IPS rules for FMC 6.4 to FMC 7
« Last post by MC on April 17, 2022, 08:40:58 PM »
Are you talking about from two different FMC, one running 6.4 to the other running 7.0? If so, not that I know of.
25
Security / Migrate IPS rules for FMC 6.4 to FMC 7
« Last post by spykas on April 08, 2022, 11:39:52 PM »
Hello ,

is it possible to migrate (export ? ) IPS rules from 6.4 to 7.0 and convert them to SNORT 3 ?

Thank you.
26
Security / Re: New user login and expired passwords
« Last post by MC on March 13, 2022, 10:25:14 PM »
What is the exact issue you are having?
27
Security / Re: New user login and expired passwords
« Last post by cerebr0_1 on March 11, 2022, 07:06:39 AM »
Hi MC
please can you tell us how did you fix the issue
28
Routing and Switching / Re: SDA Design on behalf of Christopher L.
« Last post by MC on February 05, 2022, 10:03:33 PM »
If you use switches for border node that can be virtualized, either stackable or stackwise virtual, then do so to minimize the number of BGP connection you will need to fusion device. All the underlay links in the fabric should always be redundant and routed, so no VLAN or STP should exist. You can refer to Cisco recommended design in the SDA CVD below. It covers all the different size deployments.

You are not allowed to view links. Register or Login
Pages: 1 2 [3] 4 5 ... 10
SimplePortal 2.3.7 © 2008-2024, SimplePortal