<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title>Cisco NetPro - <![CDATA[General]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=&amp;topic=&amp;CommCmd=MB%3Fcmd%3Ddisplay_messages%26mode%3Dnew%26location%3D.ee6e1f8</link>
<description><![CDATA[&lt;/span&gt;&lt;span class=&quot;bodytext&quot;&gt;Physical Security, Cisco Security Agent, Cisco Clean Access, Security design, rollout, management, and other issues]]></description>
<lastBuildDate>Fri, 3 Jul 2009 09:50:48 PST</lastBuildDate>
<generator>CCSF</generator>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<item>
<title><![CDATA[QoS Traffic shaping and peak shaping]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40a6b</link>
<description><![CDATA[Hi,
Could somebody tell me what is the difference between traffic shaping and peak shaping?

Kind Regards.]]></description>
<guid isPermaLink="false">.2cd40a6b</guid>
<pubDate>Fri, 3 Jul 2009 09:50:47 PST</pubDate>
</item>
<item>
<title><![CDATA[Dmvpn design]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40a6a</link>
<description><![CDATA[Hi,
Somebody knows what is the bw that i need on hub for 400 spokes with eigrp?
(only bw for dmvpn without consider aplications etc...)

Thanks in advance
 ]]></description>
<guid isPermaLink="false">.2cd40a6a</guid>
<pubDate>Fri, 3 Jul 2009 09:47:12 PST</pubDate>
</item>
<item>
<title><![CDATA[restore ACS v3.2 backup on an ACS v4.2 or v5.0]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40778</link>
<description><![CDATA[Hi to all,

Does anyone know if it is possible to restore an ACS v3.2 backup on a new ACS v4.2 or v5.0?? 

I have a customer that wants to perform an upgrade but i'm not sure if we will have to configure all over again in the new version.

Thanks in advance for your help.]]></description>
<guid isPermaLink="false">.2cd40778</guid>
<pubDate>Fri, 3 Jul 2009 08:30:01 PST</pubDate>
</item>
<item>
<title><![CDATA[SDM install on Windows Vista]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40a3a</link>
<description><![CDATA[I am trying to install SDM and when launching the setup.exe it immediately displays Error -6005 suggesting either closing all running programs, clearing temporary files or checking Internet connection. None of these stops the error occuring and I cannot install. The laptop has previously had SDM installed - can anyone please help?]]></description>
<guid isPermaLink="false">.2cd40a3a</guid>
<pubDate>Fri, 3 Jul 2009 07:16:58 PST</pubDate>
</item>
<item>
<title><![CDATA[EzVPN Hell....]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40379</link>
<description><![CDATA[I am trying to connect an 871 via EZVPN to a customer ezvpn server.  I am told that all is setup correctly at their end.

I have checked the username/password setup several times and gone thru setting up auto connect and acl connect.  Either way I get connected for about 10 minutes and then is drops and never comes back until I do a tunnel reset.  Am I missnig something.

any ideas would be greatly appreciated before I jump out the window....I am on the first ]]></description>
<guid isPermaLink="false">.2cd40379</guid>
<pubDate>Fri, 3 Jul 2009 07:01:45 PST</pubDate>
</item>
<item>
<title><![CDATA[latest ccsp complete study guide required ]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40a2e</link>
<description><![CDATA[Hi Friends,
I am preparing for CCSP exams, can some send me link where I can download the latest ccsp complete study guide 

Regards
Ganesh ]]></description>
<guid isPermaLink="false">.2cd40a2e</guid>
<pubDate>Fri, 3 Jul 2009 06:51:20 PST</pubDate>
</item>
<item>
<title><![CDATA[Technical assisstance required for NAC / NAP architecture for VPNs]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd409d7</link>
<description><![CDATA[We have employed dual firewall architecture at the network edge consisting of a pair of Cisco ASA 5540 with the AIP-SSM20 IPS module, and Microsoft’s ISA server with Surf Control. The Cisco ASA’s connect to the Internet and the ISA’s connect to the Internal Core LAN. Between the firewalls sits a DMZ consisting of 2 Cisco 2960’s. The Cisco ASA’s terminate all Remote Access and Site-to-Site IPSec VPNs and we will shortly be enabling full IPS functionality to scan traffic inline.

In order to further enhance the security of remote clients accessing internal resources over VPN we are thinking of rolling out a NAP / NAC solution.

Our entire LAN is Cisco (Dual 6500’s at Core and Distribution, with 2950 / 2960 at the access layer), and with heavy investment in Microsoft Active Directory we are keen to leverage a solution that plays on the strengths of both vendors.

After looking over the architecture for a NAP / NAC solution I am fairly confident that I understand how the framework fits together for the internal LAN, using the Microsoft NAP client built into the Windows OS and utilising dot1x / Cisco ACS for initial posture assessment. Microsoft policy and health servers then perform the final decision / remediation functions within AD.

However I become a little unstuck when trying to understand how a solution will work for VPNs. According the Cisco documentation,

“In a NAC Framework configuration involving the adaptive security appliance, only a Cisco Trust Agent running on the client can fulfil the role of posture agent, and only a Cisco Access Control Server (ACS) can fulfil the role of posture validation server.”

Can we use the above architecture and pass all posture assessment information from the ACS server to the same policy / health servers used on for the LAN NAC / NAP or do we have to use a different mechanism? Or can we simply bypass the Cisco ASA altogether and simply use the Microsoft NAP agent on the client and perform NAC as we have on the Internal LAN? (bearing in mind that we want to perform IPS on all inbound traffic IPSec / SSL VPN or otherwise)

Similar questions exist for the Site-to-Site VPNs. If we were to use the Cisco ASA to apply the initial NAC policy, do we simply have to provide an IP address within the tunnel to allow communication with the trust agent? or as above, can we bypass the ASA and use the Microsoft agent?

We have done some provisional testing using SSL VPNs to introduce &quot;NAC Like&quot; features, using CSD etc, but with licences costing around £7,500 and the problem of site-to-site VPNs still remaining, I thought it better to investigate a full NAC / NAP solution considering that we already have most of the infrastructure in place.

I would appreciate any assisstance that you can offer.

Chris.]]></description>
<guid isPermaLink="false">.2cd409d7</guid>
<pubDate>Fri, 3 Jul 2009 02:47:04 PST</pubDate>
</item>
<item>
<title><![CDATA[VPN client]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd4097f</link>
<description><![CDATA[guys how we config a .PCF file for cisco VPN client???? i tried to search but didnt got any info....secondly is there any good doco ?(with diagram) to show step by step guide to config cisco VPN client.....secondly i need ACS software where can i get that i have a CCO login can i download it.....Thanks guys in advance]]></description>
<guid isPermaLink="false">.2cd4097f</guid>
<pubDate>Fri, 3 Jul 2009 00:44:35 PST</pubDate>
</item>
<item>
<title><![CDATA[NAC SSO vpn: is CAS Real-IP  mode supported  ?]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd405f4</link>
<description><![CDATA[Hi all

I have been trying to setup a CAS as inline real IP gateway mode to support single sign on via a Cisco ASA running cisco vpn IPsec client.

CAS and CAM are running 4.5.1

I have followed the online guide to the letter (except for running the CAS in virtual gateway mode and doing vlan mapping) 

My vpn authentication works on the ASA and radius is passed though the CAS to the ACS server just fine.

I did a tcpdump on both cas and cam and saw the Radius accounting packet be transmitted from the ASA to the CAS and then from the CAS to the CAM, so the radius accounting 'start' packet is being transmitted upon the user being authenticated on the vpn.
 
The problem is that the laptop attempting to access the network will not display the 'auto login' screen from the CCA agent, instead the CCA agent displays the authentication request screen for user and password details.

I also following the advice of this link with no success
(Known Issue for VPN SSO Following Upgrade to Release 4.5)
&lt;A HREF=&quot;javascript:newWin('http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/45/45rn.html#wp711526')&quot;&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/45/45rn.html#wp711526&lt;/A&gt;

So I'm now doubting myself as to whether the CAS can support SSO in real IP gateway mode.

Dale]]></description>
<guid isPermaLink="false">.2cd405f4</guid>
<pubDate>Thu, 2 Jul 2009 16:54:57 PST</pubDate>
</item>
<item>
<title><![CDATA[VPN Client x64bits vista cisco 871]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd408c3</link>
<description><![CDATA[Does anyone know if exists a VPN Client for Windows Vista x64bits. My router is a 871 IOS 12.4(15).

Regards,]]></description>
<guid isPermaLink="false">.2cd408c3</guid>
<pubDate>Thu, 2 Jul 2009 11:41:24 PST</pubDate>
</item>
<item>
<title><![CDATA[Switch support by Cisco NAC]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd4083c</link>
<description><![CDATA[We are in the beginning stages of looking to implement NAC.  Our network consists of 88 locations all on the same LAN.  We want to implement OOB however we have run into a snag where there are an average of 20-30 unmanaged switches at each location that will need to be replaced.  Replacing them with Cisco's cheapest switch the 2900 will blow the project cost sky high.  Has anyone had any luck using a cheaper non-cisco switch?]]></description>
<guid isPermaLink="false">.2cd4083c</guid>
<pubDate>Thu, 2 Jul 2009 10:33:42 PST</pubDate>
</item>
<item>
<title><![CDATA[Remote Access VPN over site-to-site vpn]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd4081c</link>
<description><![CDATA[Hi,

do anyone have architecture where two different loations are connected on site-to-site vpn and users on one site initiates vpn connection to other site to access the server.It would be tunnel over tunnel.
Does anyone have deployed such scenarion or can someone provide me the pros/cons of such design..

Rgds]]></description>
<guid isPermaLink="false">.2cd4081c</guid>
<pubDate>Thu, 2 Jul 2009 05:17:41 PST</pubDate>
</item>
<item>
<title><![CDATA[PIXOS 8.0.2 and NAT.]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd3fab3</link>
<description><![CDATA[Hi all,
I need to help with interesting issue we have. 
We have created NAT from one interface of PIX  to other with access-list permiting something interesting for NAT and everything works but UDP traffic from specific pool and from Cisco VPN client no. We dont see traffic on the other side of firewall. But when we ping to the same destination (from the same pool) like for VPN traffic, traffic flows perfectly and we see xlate in PIX. Only for UDP traffic and from specific pool (192.168.3.0)from Cisco VPN, PIX doesnt create NAT xlate.

nat (_inside_) 12 access-list NAT_to_VPN
global (outside) 12 x.x.x.x netmask 255.255.255.255

access-list NAT_to_VPN extended permit ip 192.168.2.0 255.255.254.0 10.123.0.0 255.255.0.0

192.168.3.0 is included in pool 192.168.2.0/23

Any idea

gg]]></description>
<guid isPermaLink="false">.2cd3fab3</guid>
<pubDate>Thu, 2 Jul 2009 01:58:02 PST</pubDate>
</item>
<item>
<title><![CDATA[help identify CSC-SSM or AIP-SSM]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd2fc5e</link>
<description><![CDATA[Hi There,

I am having a difficulty identifying my current ASA-SSM10 module if its a AIP or CSC. Since the module is in &quot;unresponsive&quot; state.

ASA-FIREWALL# show module 1 details 
Getting details from the Service Module, please wait...
Unable to read details from slot 1
ASA 5500 Series Security Services Module-10
Model:              ASA-SSM-10
Hardware version:   1.0
Serial Number:      JAB095300MT
Firmware version:   1.0(10)0
Software version:   
MAC Address Range:  0014.6a21.b910 to 0014.6a21.b910
Data plane Status:  Not Applicable
Status:             Unresponsive

Please advise.
Will i be able to install EITHER one AIP or CSC image on the SSM-10?]]></description>
<guid isPermaLink="false">.2cd2fc5e</guid>
<pubDate>Wed, 1 Jul 2009 16:40:11 PST</pubDate>
</item>
<item>
<title><![CDATA[UCP website redirection]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd3fb1c</link>
<description><![CDATA[Ran into a small problem with the website. It works fine for those not autonomous to our network, but those autonomous, or outside our network are unable to use it. The UCP site is on a server behind an ASA, the ACS is in front of the ASA. We can use it in our office OK since we can reach the server internally, but if you are outside of our office the UCP redirects the user to the server IP after login. How can I setup UCP so it uses the public IP of the firewall and not the IP of the server after you log in to change the password? ]]></description>
<guid isPermaLink="false">.2cd3fb1c</guid>
<pubDate>Wed, 1 Jul 2009 14:10:23 PST</pubDate>
</item>
<item>
<title><![CDATA[CTA and userenv.dll]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd4070d</link>
<description><![CDATA[Can someone explain why CTA waits for Microsofts userenv.dll to complete before it will run?  Is there a way to prebent this?

]]></description>
<guid isPermaLink="false">.2cd4070d</guid>
<pubDate>Wed, 1 Jul 2009 10:46:00 PST</pubDate>
</item>
<item>
<title><![CDATA[ACS Appliance Upgrade path]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd3fb9f</link>
<description><![CDATA[I am seeing patches and CSUpdate files with the same release date. My current version is Acs-4.2.0.124.9-CSUpdate fix  Base image 4.2.0.107, Appliance Management Software 4.2.0.124,

Question is which patch do I apply, the Cumulative, the CSUpdate, or both. Do I need to apply them one after the other, or is the .12 patch a rollup that includes the fixes in the previous versions, 10 and 11. 

One other thing, other than physically going to the colo and reading it off the server itself, where can I find the serial number of the unit. ]]></description>
<guid isPermaLink="false">.2cd3fb9f</guid>
<pubDate>Wed, 1 Jul 2009 10:03:28 PST</pubDate>
</item>
<item>
<title><![CDATA[ACS 3.3 Media]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd35dac</link>
<description><![CDATA[One of our customers lost the Media (CDs) for their ACS server. Is there anyway to get a copy of this for them?

You can download recovery cd's for certain versions of the appliance but not for the windows server.]]></description>
<guid isPermaLink="false">.2cd35dac</guid>
<pubDate>Wed, 1 Jul 2009 09:58:48 PST</pubDate>
</item>
<item>
<title><![CDATA[VPN - Prompt to for user to change SSL Client password]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd23d5e</link>
<description><![CDATA[Please tell me if there is a way for the user to change their own password once they login with the SSL VPN Client. I would like for my users to have to change their password after first login &amp; after so many days. Is it possible for users to change their login password for the SSL VPN Client?]]></description>
<guid isPermaLink="false">.2cd23d5e</guid>
<pubDate>Wed, 1 Jul 2009 09:57:05 PST</pubDate>
</item>
<item>
<title><![CDATA[NAC not doing posture assessment]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd3f7b2</link>
<description><![CDATA[Hello All,

I am having diffculty with NAC where its not doing posture assessment. I ran through the configuration guide and followed it to the T but still no luck. I am running NAC 4.5(1) for In Band wireless. Any ideas as to what i should be looking at next?

Thanks,
G]]></description>
<guid isPermaLink="false">.2cd3f7b2</guid>
<pubDate>Wed, 1 Jul 2009 06:46:27 PST</pubDate>
</item>
<item>
<title><![CDATA[NAC Manager Failure during OS booting]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd405dc</link>
<description><![CDATA[Guys, i got a NAC manager appliance from cisco on which the NAC manager is installed. I configured failover on the server and during reboot, the boot stops at the line below and doesn't continue th enormal boot procedure: 
EXT3-fs: mounted filesystem with ordered data mode

I can ping the server, but i can't access its web interface.So I tried to access the appliance via ssh and i succeeded. However the http service is not starting: 
# service httpd start
[root@nacm1 ~]#Starting httpd: Syntax error on line 356 of /etc/httpd/conf/httpd.conf:
DocumentRoot must be a directory
[FAILED]

I have another NAC manager, and i compared the /etc/httpd/conf/httpd.conf file on both appliances and its the same.

Your help is really appreciated

Moustafa]]></description>
<guid isPermaLink="false">.2cd405dc</guid>
<pubDate>Wed, 1 Jul 2009 02:00:03 PST</pubDate>
</item>
<item>
<title><![CDATA[route remain in the routing table after disconnect vpn client]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc0ce55</link>
<description><![CDATA[I have configured a 2811 with pppoe and fix ip address with adsl, the use it as easy vpn server and another 2811 configured as easy vpn client also use pppoe connect to random ip address adsl.
I just want to ask that why the route is remained after i disconnect remote easy vpn.]]></description>
<guid isPermaLink="false">.2cc0ce55</guid>
<pubDate>Tue, 30 Jun 2009 23:54:18 PST</pubDate>
</item>
<item>
<title><![CDATA[ASA 5550 - there is no record in the log for Teardown]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd3f9be</link>
<description><![CDATA[Hi all! 

We have an ASA 5550, that for some connections there is no record of Teardown. 



Logs of connections without Teardown:

3 - 2009/06/24 00:18:24.235 BRT     10.x.x.x    %ASA-6-302013: Built inbound TCP connection 88873324 for outside:172.x.x.x/22852 (192.168.x.x/22852) to intf3:172.23.x.x/6090 (10.12.x.x/6090)

4 - 2009/06/24 00:18:57.734 BRT     10.x.x.x    %ASA-6-302013: Built inbound TCP connection 88873415 for outside:172.x.x.x/22881 (192.168.x.x/22881) to intf3:172.23.x.x/6090 (10.12.x.x/6090)

5 - 2009/06/24 00:19:43.514 BRT     10.x.x.x    %ASA-6-302013: Built inbound TCP connection 88873611 for outside:172.x.x.x/22881 (192.168.x.x/22881) to intf3:172.23.x.x/6090 (10.12.x.x/6090)

6 - 2009/06/24 00:20:17.012 BRT     10.x.x.x    %ASA-6-302013: Built inbound TCP connection 88873735 for outside:172.x.x.x/22909 (192.168.x.x/22909) to intf3:172.23.x.x/6090 (10.12.x.x/6090)

7 - 2009/06/24 00:21:02.807 BRT     10.x.x.x    %ASA-6-302013: Built inbound TCP connection 88873897 for outside:172.x.x.x/22909 (192.168.x.x/22909) to intf3:172.23.x.x/6090 (10.12.x.x/6090)

8 - 2009/06/24 00:21:36.290 BRT     10.x.x.x    %ASA-6-302013: Built inbound TCP connection 88874125 for outside:172.x.x.x/22937 (192.168.x.x/22937) to intf3:172.23.x.x/6090 (10.12.x.x/6090)



Logs of connections with Teardown:

1 - 2009/06/23 23:24:09.468 BRT           10.x.x.x %ASA-6-302013: Built outbound TCP connection 88858554 for outside:192.168.x.x/80 (192.168.x.x/80) to inside:10.58.x.x/1915 (192.168.x.x/47736)

2 - 2009/06/23 23:24:34.435 BRT           10.x.xx %ASA-6-302014: Teardown TCP connection 88858554 for outside:192.168.x.x/80 to inside:10.58.x.x/1915 duration 0:00:24 bytes 107762 TCP FINs



Logging configuration: 

ASA-EXT-07# sh run a
ASA-EXT-07# sh run all log
ASA-EXT-07# sh run all logging
logging enable
logging buffer-size 4096
logging asdm-buffer-size 100
logging monitor debugging
logging buffered debugging
logging trap debugging
logging host intf3 10.254.254.28
logging flash-minimum-free 3076
logging flash-maximum-allocation 1024
logging rate-limit 1 10 message 620002
logging rate-limit 1 10 message 717015
logging rate-limit 1 10 message 717018
logging rate-limit 1 10 message 201013
logging rate-limit 1 10 message 201012
logging rate-limit 1 10 message 405002
logging rate-limit 1 10 message 421007
logging rate-limit 1 10 message 405001
logging rate-limit 1 10 message 421001
logging rate-limit 1 10 message 421002
logging rate-limit 1 10 message 710002
logging rate-limit 1 10 message 209003
logging rate-limit 1 10 message 209004
logging rate-limit 1 10 message 209005
logging rate-limit 1 10 message 431002
logging rate-limit 1 10 message 431001
logging rate-limit 1 10 message 110001
logging rate-limit 1 10 message 450001


Appreciate any help!]]></description>
<guid isPermaLink="false">.2cd3f9be</guid>
<pubDate>Tue, 30 Jun 2009 13:23:48 PST</pubDate>
</item>
<item>
<title><![CDATA[Restricted Access on Remote Access]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40386</link>
<description><![CDATA[Hi,

Is it possible to configure Remote Access on ASA and restrict users to specific host on the LAN.
Users should be created on ASA.

If possible,Can someone help with config]]></description>
<guid isPermaLink="false">.2cd40386</guid>
<pubDate>Tue, 30 Jun 2009 13:16:57 PST</pubDate>
</item>
<item>
<title><![CDATA[Check cpu processes on a Pix 525 Version 7.2(2)]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd3fe05</link>
<description><![CDATA[Hi to all,

A few hours ago i had a high cpu utilization on my Pix 525 Version 7.2(2), i wanted to check what process was taking all the CPU but i noticed that there is no command &quot;show processes&quot;.

I was able to see the percent of cpu utilization (show cpu, show cpu usage) but not the list of processes, does anyone know how can I check this??

Thanks in advance for your help.]]></description>
<guid isPermaLink="false">.2cd3fe05</guid>
<pubDate>Tue, 30 Jun 2009 10:22:34 PST</pubDate>
</item>
<item>
<title><![CDATA[same-security access problem]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40375</link>
<description><![CDATA[I'm trying to set-up two networks on two separate ASA ports and make them communicate with each other. I'm using the same security level (100) for them and I've checked the option for same-security level communication in ASDM. The problem is that I can't make this scenario work. The ASA interfaces are reachable from their networks but I can't ping between them(across the ASA). ACLs are set on permit any and I've set up also nat exemptions. The packet tracer shows no problem but ping or traceroute doesn't work. I also enabled icmp inspection. It's driving me crazy. Anyone know what I'm missing here? There is also a third interface used for internet access with NAT and it works.]]></description>
<guid isPermaLink="false">.2cd40375</guid>
<pubDate>Tue, 30 Jun 2009 06:12:15 PST</pubDate>
</item>
<item>
<title><![CDATA[NAC, PBR but no redirect webpage]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd33a6f</link>
<description><![CDATA[Hi guys...

I need some assistance....We set up the NAC as Out-of-Band Real-IP Gateway...We have PBR set up, and we are able to get ip address (authentication vlan), but no redirect webpage...

any assistance would be greatly appreciated...


]]></description>
<guid isPermaLink="false">.2cd33a6f</guid>
<pubDate>Tue, 30 Jun 2009 05:44:46 PST</pubDate>
</item>
<item>
<title><![CDATA[ASA 5540 Version 7.2.3 Policy Updates]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd40456</link>
<description><![CDATA[Hi,

We are facing a strange issue where in the current Policy does not work after a month or so, but if we remove the policy and add it once again it starts working fine, not sure whether it has got something to do with BUG with the current version.

Please help.

Thanks,
Vinay
]]></description>
<guid isPermaLink="false">.2cd40456</guid>
<pubDate>Tue, 30 Jun 2009 04:37:40 PST</pubDate>
</item>
<item>
<title><![CDATA[crypto isakmp disconnect-notify]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd3fcc1</link>
<description><![CDATA[Hi All,
I know that ASA has this command to disable the notification dialog box in the remote Easy VPN client. But I cannot find out this command in IOS.
Anyone know whether IOS has this command? I have deployed auto connect feature on my vpn clients. I want to resolve this problem because VPN cannot re-connect after the network interruption.

Thanks a lot!!
Jason]]></description>
<guid isPermaLink="false">.2cd3fcc1</guid>
<pubDate>Tue, 30 Jun 2009 00:31:14 PST</pubDate>
</item>
<item>
<title><![CDATA[CSM 3.1.1 Log files destination change]]></title>
<link>http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;type=rss&amp;forum=Security&amp;topic=General&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd403d5</link>
<description><![CDATA[Hi,

We are running with CSM 3.1.1, currently it is installed in C: drive,and the logs take much of the space of the C: drive, is there any way to change the default location of the logs to be generated, like in D: drive.


Thanks,
Vinay]]></description>
<guid isPermaLink="false">.2cd403d5</guid>
<pubDate>Mon, 29 Jun 2009 22:50:48 PST</pubDate>
</item>

</channel>
</rss>
