The ACP prevention policy and intrusion

Hi all

What happened to apply a strategy of access control with some rules and some Intrusion prevention policy in an architecture where the ips is deployed in passive mode with a mirror port?

Is it advisable?

Thanks in advance

Lore

Hi Lore,

Deployment of the IPS in passive mode is quite common, but it has its own deployment limits (see below).

Usually, in a deployment passive IPS, firepower system monitors traffic circulating on a network using a switch, SPAN or mirror port. The SPAN port or mirror allows for traffic to be copied to other ports of the switch. This provides the visibility of the system within the network without being in the flow of network traffic.

Please keep in mind, when it is configured in a passive deployment, the system cannot take certain actions such as blocking or traffic shaping. Passive interfaces receive all traffic without condition, and no traffic received on these interfaces is broadcast.

Some other info and configuration:

Cisco.com Guide: http://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuratio...

Cisco Validated Design: http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-...

Thank you

Guillaume

Rate if this can help!

Tags: Cisco Security

Similar Questions

  • Prevent the user account to change the time? Policy and security?

    I came across this site:

    http://www.SevenForums.com/tutorials/113557-date-time-allow-prevent-users-groups-changing.html

    I followed him.

    So, I logged in using the account that I am limited. It worked like a charm. I can't change the date and time. But problem, using the limited account, I can also access the "secpol.msc" and change the settings. If the person that I have limited knows how to make their account able to change the date and time using the secpol.msc, so it would be useless.

    What can I do to prevent some users from accessing the "secpol.msc"?

    Hi Erebore,

    Please follow the steps below and check to prevent certain users to access secpol.msc

    1. To open the local security policy MMC snap-in, click Start, type secpol.mscand press ENTER.
    2. In the console tree, double-click Application control policies, and then double-click AppLocker.

    3. Right-click executable rulesand then click create default rules.

    4. Three rules are created and listed in the Details pane of the MMC console:
    • To allow all users to run files in the default Program Files folder.
    • To allow all users to run files in the Windows folder.
    • Allow members of the built-in Administrators group to run all the files.

    When you create these three rules, you automatically prevent all administrator users to run programs that are installed in their user profile folder.

    I hope this helps. Back to us for any additional information on the question above. We are happy to help you!

  • How to prevent spam and the dating of the queries

    How to prevent spam and dating asking to come in my junk mail too much looking forward this junk e-mail

    If the emails are from the same source or have a constant content, you can write a rule in Mail/preferences/Rules. Example below.

  • I use to manage my DSL modem via an ip address. When I enter FF8 I wonder where to save the file. Why and how can I prevent the FF8 to do this?

    I use to manage my DSL modem via an ip address. When I enter FF8 I wonder where to save the file. Why and how can I prevent the FF8 to do this?

    And now, whenever I'm in an ip address that I wonder if I want to download the file.

    This happens when the modem server does not send the file in text/html, but with a different MIME type.

    I tried adding index.html in the event that the server can send this file as text/html.

    If your DSL modem has a support Web site, then you can try asking it there advice on how to configure the server modem.

  • What are the differences between the services and site domain group policy and group policy?

    What are the differences between the services and site domain group policy and group policy?

    Server must wonder about the Technet site.  http://social.technet.Microsoft.com/forums/en-us/home

  • C00D11B1 error message prevents the films currently playing and no noise all trying to play music.

    Media Player 11

    Hi John Shrek,.

    Welcome to the Microsoft Answers community.

    I will need more information to help you better.

    ·         Did recent changes to the computer?

    ·         Is this the first time you arrive on this issue?

    ·         Did you use any third party registry patches or updates recently?

    Generally, this error occurs when there is a problem with one of the sound devices in the computer, such as a sound card or sound controller. However, this error can also occur if there is a problem with the file or the Internet connection.

    Update the device driver for the sound card or audio controller. To determine if an updated driver is available, visit the website of the manufacturer of the component, or visit the Microsoft Update Web site: http://update.microsoft.com (http://update.microsoft.com).

    Use Device Manager to determine the State of the sound card or audio controller. Follow these steps:

    1. click on start, type devmgmt.msc in the start search box and press ENTER.

    If you are prompted for an administrator password or a confirmation, type the password or click on continue.

    2. expand sound, video and game controllers, and then look for the name of the sound card or audio controller.

    If your audio device is listed, but a red "X" appears next to the device, the device is disabled. To activate the device, right-click the icon, and then click Activate.

    If the audio device does not appear in the list of audio devices, expand other devices. If the multimedia Audio controller appears in the list, right-click on the icon and then click on update driver or update driver software. Follow the instructions to install the driver.

    You can also go to the website of the manufacturer of the computer and install the appropriate driver.

    Open Internet Explorer in Administrator Mode and check if you can play.

    It can also occur because of a database of digital rights (DRM) corrupt management.

    Follow the steps below to change the registry value to disable ProtectedAudioDG:

    1. Click Start, type regedit in the search box and press ENTER.

    If you are prompted for an administrator password or for confirmation, type the password or click on continue.

    2. Locate and then click the following key:

    HkeyLocalMachine\Software\Microsoft\Windows\CurrentVersion\Audio

    3. Locate and double-click DisableProtectedAudioDG.

    Note: If this key does not appear in the registry, you can these steps.

    4. According to the value data, change the value from 1 to 0.

    Restart the computer.

    It should work fine now.
    If the problem still persists to upgrade your security components by visiting the website http://drmlicense.one.microsoft.com/Indivsite/en/indivit.asp

    For more information visit http://support.microsoft.com/kb/933448

    For added protection, back up the registry before you edit it. Then you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click on the number below to view the article in the Microsoft Knowledge Base:

    322756 (http://support.microsoft.com/kb/322756/ ) how to back up and restore the registry in Windows

    Change the settings of the REGISTRY can cause serious problems that may prevent your computer from starting properly. Microsoft cannot guarantee that problems resulting from the REGISTRY settings configuration can be solved. Changes to these settings are at your own risk

    Hope this information is useful.

    Let me know if it worked.

    Thank you, and in what concerns:

    Umesh P - Microsoft Support

    Visit our Microsoft answers back Forumhttp://social.answers.microsoft.com/Forums/en-US/answersfeedback/threads/ and tell us what you think.

  • Activate the user audit logs and hide the other audit logs account system on computers in a domain by using Group Policy

    Hello

    Please could someone advise me on how to activate the user audit logs and hide the other audit logs account system on computers in a domain by using Group Policy. Your help would be much appreciated.

    Kind regards

    RocknRollTim

    Hello

    Please contact Microsoft Community.

    We have a specific forum for the computers in the domain and they are experts in this field of investigation and would be in a better position to address the concerns. So refer to the link below and post your query on the TechNet Forums.

    https://social.technet.Microsoft.com/forums/en-us/home

    I hope this helps. If you have any questions on Windows, please answer. We will be happy to help you.

  • Windows 7; Windows firewall prevents the discovery network, files and printers, sharing, public folder sharing and streaming media

    Windows Home Premium SP1, completely up to date.  Windows Firewall is enabled.

    Try to keep the file sharing and printers on a home network.  Try changing the settings on the control panel; All Control Panel items: Center network and sharing; Advanced sharing settings.

    When I try to change the option buttons for sharing, then click on save changes at the bottom of the page, the screen jumps to the network and sharing Center.  Object entering the settings advanced, no parameters have been recorded.   The comoputer restarting does not help.  I checked that the following services are running and set to automatic according to the http://answers.microsoft.com/en-us/windows/forum/windows_7-networking/cant-turn-on-network-discovery-and-media-streaming/98654e71-4bff-4dd3-acec-ffc3524d44a4;

    The base filtering engine
    DNS client
    Function Discovery Provider Host
    Function Discovery Resource Publication
    HomeGroup listener
    HomeGroup provider
    Server
    SSDP Discovery
    UPnP device host
    Windows Firewall

    When I stop the Windows Firewall service, I can activate the sharing I want.  Of course the windows firewall prevents sharing I would do on my network.

    I'm uncomfortable with Miss having a firewall work on my computer.  How to configure my Win 7 machine windows firewall to allow communications with my homegroup?  I tried to restore the default values.  This did not allow the communication.  I tried to find the homegroup settings in the advanced settings of the windows firewall.  No luck there.

    What should I do to configure my windows firewall to allow network discovery and file sharing of printers and media streaming and sharing?

    Hi stephanie,.

    Thanks for joining us out on Microsoft Community Forums.

    Looks like the Windows firewall prevents the discovery network, files and printers, sharing, public sharing of files and streaming media. We will analyze and identify the cause of the problem.

    You have a third-party antivirus installed on the computer program?

    Method 1:

    To turn on network discovery

    1. Open advanced sharing settings by clicking the Start button, then Control Panel. In the search box, type network, click Network and sharing Center, and then, in the left pane, click on change settings for sharing advanced.
    2. click on the chevron to expand the current network profile.
    3. click turn on network discovery and then click on save changes. If you are prompted for an administrator password or a confirmation, type the password or provide
    confirmation.

    The article below explains all about the network discovery:
    http://Windows.Microsoft.com/en-us/Windows7/enable-or-disable-network-discovery

    If any of these responses not solve the issue, let us then run the sfc scan and check if any file system is corrupt. I also recommend to perform a clean boot in order to find the root cause of the problem.

    Method 2:

    Use the (SFC.exe) System File Checker tool to determine which file is causing the problem and then replace the file. To do this, follow these steps:

    a. open an elevated command prompt. To do this, click Start, click programs, accessories principally made, right-click Guest, and then click Run as administrator. If you are prompted for an administrator password or a confirmation, type the password, or click on allow.

    b. type the following command and press ENTER:
    sfc/scannow

    The sfc/scannow command. analyzes all protected system files and replaces incorrect versions with appropriate Microsoft versions.

    More information on SFC scan found in this document:
    http://support.Microsoft.com/kb/929833

    See also:

    Open a port in Windows Firewall

    http://Windows.Microsoft.com/en-in/Windows7/open-a-port-in-Windows-Firewall

    Allow a program to communicate through Windows Firewall

    http://Windows.Microsoft.com/en-in/Windows7/allow-a-program-to-communicate-through-Windows-Firewall

    Hope this information helps. Get back to us if you have more queries about Windows.

  • How to prevent the installation of software and IE extensions / toolbars, etc.

    I try to help a small business at home with a Windows 7 PC with IE 9. The PC is used for normal business purposes: Microsoft Office documents, e-mail (AOL app), video editing and burn them on DVD or download YouTube and Vimeo, and research in Internet Explorer for commercial use normal and legitimate

    My questions are (explained later):

    All the PCs here have parental control of Microsoft and Microsoft Security Essentials installed. None of the PC should be able to be used for something ELSE (not only internet) between midnight and 08:00.
    1. How can I get Internet Explorer 9 on Windows 7 automatically restore the State by default when it is closed? As if it were a PC in an internet café, library or school? This allows to avoid the (intentional or accidental) installation of toolbars, extensions, etc. in IE 9, if possible, I'd like to keep Google as the default search provider and homepage; In addition, the extensions 'regular' such as Flash Player, Real Player and Acrobat Reader must remain in place and JavaScript should work.
    2. the son managed to resume using his own PC (and perhaps the PC business) at limited hours. I guess he got Windows 7 SysInternals disk to remove the administrative password. Is there a way I can stop that then reapply restrictions? Maybe he simply restored the system from the recovery partition or reinstalled Windows, so I need a way to prevent these things from happening as well. A firmware password would do the trick?

    This probably wouldn't have happened if there was a way to allow installation of the software on a Standard account. On the own PC of the son, it's okay if it installs the software, browser toolbars and so on--even if it is malware. It is only the PC that should be free of this professional. It is also possible that it has installed this junk on the Professional PC as a form of punishment.
    It is not possible to force users to use Firefox or Chrome instead of IE. And IE suffered from some bad extensions that were installed in Chrome.
    Explanation:
    The owner of the company adult son uses this PC occasionally working for the company, but mostly for its own use. The son, who can be a little mentally ill and lives with his father in the House where the business is, continued installation providers extensions, toolbars and search for malware, unwanted, unsafe in Internet Explorer and change the homepage. Office workers may have also unintentionally installed some malicious software search engines.
    Occasionally, the son works for the company, so must have the PC of the company. However, he often uses the PC for its own purposes, which includes things like trying to download protected content (movies, television and music) without having to pay for it. It seems that he sometimes spend time free looking for games. (Before I put on the parental control, it had installed several of them. There still frequently installed toolbars, extensions and search providers in Internet Explorer to facilitate this [protected media download] and [probably] some of them gets simply by visiting the types of malicious websites that claim to offer free stuff. The son has four pieces of his own, which are almost unusable due to multiple malware infections.
    Owner of the company I was install the parental control on the PC of the son in addition to the PC business to prevent the use of any computer between midnight and 08:00 when the son is supposed to sleep or study and not play games or use the computer for something ELSE. According to the owner of the company, the son psychiatrist said that the son must sleep during those hours every day.
    Currently, it is not possible for me to question the son - it is of course very unhappy about not being able to install software on PCs own hie. Not that I was all happy that all this, but he isn't one to pay me.
    Sorry, this has been so long. The situation is a little stressful.

    A knowledgeable user can bypass/get around any account login admin password, by using any method found in a search on the internet.

    You can try to set up separate for normal use restricted user accounts.

    You can also configure another admin account, with the reset/recovery disk of password for your own use. (In which case a user causes problems in their attempt to circumvent restrictions)

    Assuming that PCs are networked / connected via a routor, a decent has the ability to restrict the sites accessible both to prevent net access between certain hours, on a per PC basis.

    There is software of third parties, such as used on some PCs consulted by the public in the scenario you mentioned, although how it would affect normal business type useage I could say.

    Certain third-party Internet security applications also have the ability to restrict access/use their own parental controls

  • My computer is connected to the Windows 2008 R2 server and some of the users on this computer receive their network drive mapped on group policy and some do not.

    My computer is connected to the Windows 2008 R2 server and some of the users on this computer receive their network drive mapped on group policy and some do not.  I find nothing in Event Viewer that shows that there is a problem.  Please let me know what to do to get the disks appears

    Original title: Network Networking file sharing file sharing file sharing file sharing discovery sharing Fileshare share shared

    Hi,

    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.

    TechNet Forum

    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer

     

    Hope this information helps.

  • Inadvertently, I moved my cursor using the touchpad and it decreased my policy and I can't go back to a larger size. my daughter thinks it has something to do with scrolling

    Inadvertently, I moved my cursor using the touchpad and it decreased my policy and I can't get it for a larger size. my daughter thinks it has something to do with scrolling

    You did not mention this program what happens to, but even in the case of the office, there are standard methods to adjust the zoom level with the keyboard.

    Press Ctrl and more (e, g +) together to increase the zoom level and Ctrl and less (for example) - all to reduce. The keys more or less can be those at the top of the classic (for example to the left of the back) keys or the numeric keypad if you have one.
    Alternatively, you can hold down the CtrI down while turning the scroll of the mouse wheel to adjust the zoom level of the window that the cursor of the mouse is on.
    Many programs have a slider or box to adjust the zoom level. It is usually at the bottom right of the application window. Similar zoom adjustments may be able to make the menu display, Zoom the program.
  • What is the tool to bless and why it prevents a clean reinstall?

    I'm helping a friend who has erased his internal HD due to a problem thinking it was a startup disk. She also didn't

    have a backup.

    I made an installation on a USB disk using diskmaker. When I try to start now the Option button, I get the recovery partition disk utility.

    When I select the bootable as the boot floppy installation disk, I get a message that it cannot be used as the startup disk. The Bless tool was unable to put the current startup disk.

    What is the tool to bless and is there something that can help me to do a clean install of El Capitan?

    Thank you

    Well, first of all, if you used your identifier Apple to download the operating system and then using your license to install on the machine of someone else will not work because the license is not transferable and is linked to the Apple ID used to get. the recipient would not be able to update the apps or reinstall because they need your Apple ID and password.

    If you use recovery, why not just use to reinstall the OS - have you tried designate the hard drive? I would try disk utility to repair the hard drive and the re-partition/format. As far as I know, bless tool is part of the operating system and tries to find a boot disk; I looked, and although I found a lot of questions, I was not able to find a definitive answer.

  • I did the update of windows, and there was a lot of mistakes. I then tried to restart the system, and it is said that acro32.exe is it prevents to close?

    Original title: acro32.exe

    I did the update of windows, and there was a lot of mistakes. I then tried to restart the system, and it is said that acro32.exe is he keep awake. What is and how to fix it?

    If you really see a message about "acro32.exe" is probably malware you should scan your computer with the virus eset online scanner and then download, update and run the free version of MalwareBytes AntiMalware.

    If, as is most likely, the message concerns AcroRd32.exe, the main executable file of Adobe Reader.  Go to control panel > programs and features and uninstall Adobe Reader.  If you have problems uninstalling Adobe Reader, see--> http://labs.adobe.com/downloads/acrobatcleaner.html

    Assuming that things patches, install Foxit Reader (free) instead--> http://www.foxitsoftware.com/Secure_PDF_Reader/

    Or, if you really want Adobe Reader back, go here--> https://get.adobe.com/reader/ (remember to uncheck the box to install McAfee Security Scan or any other 'add-on free")

  • Prevent the user from printing and see some pages

    Here is the scenerio:

    The form has 4 pages.  I want only the user to see and know about page 1.

    I need to batch print the other 3 pages, each page in a separate batch

    Here is what I tried and the question resulting:

    1 format pages 2,3,4 as visible print only

    a. the user may say there are 3 other pages - they appear in white

    b. the user may see them if they decide to print

    2 format pages 2,3,4 as visible print only and restrict printing to the user

    a. I can't print without having to open each one with a password - works well with printing of lots per page

    3 format pages as hidden 2,3,4 - the user cannot tell or see the other 3 pages but:

    a. I can't print the pages

    3 format pages 2,3,4 as hidden and have the form submitted as xml and import them into the complete PDF

    a. There are fields that are changed dyamically based on the selection of the user (ie. selection of fonts), so that the xml import does not work for this

    Any ideas on how to "get my cake and eat it too."

    Hello

    You could try a hidden field that seeks the username «»

    There are security problems, and the script has to be in a position of trust. You can make this place a Javascript file inside the Acrobat folder. The penalty usually with trusted fuctions is that you must send to each user a copy of the js file and it should also put it in the appropriate folder.

    In your case is not a problem, because you only want the js file on your computer and do not need to distribute it to others.

    When you put the (downloaded) file in Acrobat / folder Javascript, Acrobat will load it automatically.

    In Acrobat, make sure that you have defined a 'name' in Edition / Preferences / Identity tab:

    When you open the PDF document, your user name will be on the field. This only happens if the js file is loaded in the correct folder on the computer that you are using.

    Once it's working, it's a simple step to include an if statement in the textfield, after the script located in the initialize event:

    If (this.rawValue == "lfalke") / / or whatever your username is set on...

    {

    Page2.presence = "visible";

    page3. Presence = "visible";

    page4. Presence = "visible";

    }

    on the other

    {

    Page2.presence = 'hidden ';

    page3. Presence = "hidden";

    page4. Presence = "hidden";

    }

    This means that the visibility of the three pages would be automatic. User with the js file AND your username could see pages 2-4, everyone would not see these pages.

    I know it's a little complicated, but once put in place it should continue to work OK.

    Hope that helps,

    Niall

  • Political strategy of access control and Intrusion

    Hi all

    I am a student for certification ips.

    I do not understand the difference between the political Intrusion and access control strategy...
    Maybe the difference is: ACP's ip and the control ports and Intrusion policy antivirus, file inspection etc etc?

    Thanks in advance

    Specify you rules in your access control strategy.

    For each of these rules, you can ad a political Intrusion and a file.

Maybe you are looking for

  • Firefox hangs at startup: update / reinstall / profile wipe / purge addon has not set

    Hello As the subject says, my Firefox crashes now immediately at startup. (It's on Windows 10 64-bit.) Here is what I tried which did not fix the crash:-Refresh-Reinstall-Disable all addons-uninstall the software which provides plugins (Flash, Acroba

  • How to connect by facebook account on Skype for iphone

    Hi, I connect to Skype from my facebook account on my computer, but I can't find the link for facebook in the login screen of Skype for iphone account. I tried to use Skype account name shown in the software "facebook:XXXX" to connect, but it still d

  • How to activate the avg firewall on in the 2012 edition

    How to activate the avg firewall on in the 2012 edition, when I scanned with mcafee his watch this avg firewall is disabled. only windows firewall is enabled, then how to activate the avg firewall on. Please, help me to overcome this problem.

  • elitbook HP 2740 Important Bios

    I downloaded this player ' HP Notebook System BIOS update VERSION: F.04 "of your Web site and after this set.The unit does not light Then the machine was not able to open any interface In this case, can someone help meSend me a valid BIOS update file

  • OfficeJet6700: Print only two color cartridges

    My Officejet 6700 is only an impression with 2 cartridges 3 colours.  Print cartridges Magenta and yellow, but isn't the Cyan.  I ran tests, cleaned and aligned the printer but when I print my tests I see the blocks where the results of the Cyan cart