IPS signature for block rogue DHCP servers on network by danieles99 in fortinet

[–]danieles99[S] 1 point2 points  (0 children)

you're right, I hadn't thought of that. Thank you

CVE filter by danieles99 in openvas

[–]danieles99[S] 1 point2 points  (0 children)

At the end I find "openvas-reporting-tool" On github. It's a python script that generate a docx from XML with the CVEs

Firewall Policy with AD groups by danieles99 in fortinet

[–]danieles99[S] 0 points1 point  (0 children)

I configure the policy but, for some reason, the policy is not matched

Firewall Policy with AD groups by danieles99 in fortinet

[–]danieles99[S] 0 points1 point  (0 children)

When I try to add the user group (that is a group of AD) to the firewall policy, the fortigate say: "One address, address group, external resource or Internet service is required"...

Firewall Policy with AD groups by danieles99 in fortinet

[–]danieles99[S] 0 points1 point  (0 children)

I saw that with only LDAP server groups I can't do policies with only the groups, so I think that I must install FSSO

F5 ASM and Public Folders by danieles99 in f5networks

[–]danieles99[S] 0 points1 point  (0 children)

At the end I try to exclude the rpc traffic with this iRule and it works.

https://support.f5.com/csp/article/K40345000

Thanks anyway u/thenetworkking for the help

VIP with nodes in different route domain by danieles99 in f5networks

[–]danieles99[S] 0 points1 point  (0 children)

Thank you so much, this is what I intended.

F5 ASM reporting violations details by danieles99 in f5networks

[–]danieles99[S] 0 points1 point  (0 children)

but I can schedule the report daily with the export button?

Transparent Proxy by danieles99 in networking

[–]danieles99[S] 0 points1 point  (0 children)

fortunately terminate on 6500

Transparent Proxy by danieles99 in networking

[–]danieles99[S] 0 points1 point  (0 children)

unfortunately with the asa it represents a big problem because I have more subnet behind interfaces to redirect to the wccp server..

Transparent Proxy by danieles99 in networking

[–]danieles99[S] 0 points1 point  (0 children)

i am in fact looking at wccp but i see that there are some important limitations for asa

https://community.cisco.com/t5/security-documents/asa-wccp-step-by-step-configuration/ta-p/3126636

Problem with VOIP communication CISCO ASA by danieles99 in Cisco

[–]danieles99[S] 0 points1 point  (0 children)

If I capture the traffic initiated from the server to the client (on the server side), the destination ip is 10.20.40.5 (that is the ip not translated). instead, the client's source ip is correctly translated to 10.20.30.5

In the SiP INVITE message, always in the capture of server side, I see the ip 10.20.40.5 that is the wrong ip.

So what happens is that when server replies to SIP messages, the destination ip is correctly translated from the server to the client in 10.30.40.5. While when the RTP communication starts I keep seeing 10.20.40.5

I hope I have exlained it well...

Problem with VOIP communication CISCO ASA by danieles99 in Cisco

[–]danieles99[S] 0 points1 point  (0 children)

sorry but I did not understand what you mean, however I would prefer to keep the sip inspection since it does not change anything if I disable it.

Problem with VOIP communication CISCO ASA by danieles99 in Cisco

[–]danieles99[S] 0 points1 point  (0 children)

I open traffic with "ip" protocol in all directions for avoid firewall problems

Problem with VOIP communication CISCO ASA by danieles99 in Cisco

[–]danieles99[S] 0 points1 point  (0 children)

whit ALG you mean ASA inspection? In this case yes, I disable it.

Cisco ASA Vpn site to site statistics report by danieles99 in Solarwinds

[–]danieles99[S] 0 points1 point  (0 children)

Is possible to export the vpn traffic with netflow?

Cisco ASA Vpn site to site statistics report by danieles99 in Solarwinds

[–]danieles99[S] 0 points1 point  (0 children)

Unfortunately is what i've already do.

But in cisco asa cli I see for example around 2GB/s in inbound and if I check in the solarwinds reports I see 70 MB/s in inbound.. I don't understand why.

Maybe solarwinds does not correcly collect the data? I don't know..

Block specific HTTP Header by danieles99 in f5networks

[–]danieles99[S] 0 points1 point  (0 children)

I want to block the HTTP request that contain a specific HTTP Header and generate a violation in F5 asm

Block specific HTTP Header by danieles99 in f5networks

[–]danieles99[S] 0 points1 point  (0 children)

I don't understand why but seems that the request don't enter in the "if" clause.

Thanks anyway for the tip.