Home » Security

Cisco ASA: Routing packets based on where the connections started from

Question:
We have a Cisco ASA 5505 (version 8.2(2)) with three interfaces:
outside: IP address 11.11.11.11, this is the default route
inside: IP address 10.1.1.1, this is the local subnet
newlink: 22.22.22.22, this is a new internet connection.
We need to move VPN users from the 11.11.11.11 address to the 22.22.22.22 address, and we’re using SSH on the ASA as [...]

Need assistance with Snort IDS

Question:
Reading pcap files with snort
Hello, I am running snort v2.8.5.3 on Win XP. I have several pcap files that I want to analyze. I tried the -r command and I did not receive any results. I have my pcap files in the bin folder where snort.exe is located. This is how I am running snort
c:\snort\bin>snort [...]

Configure Squid on XP

Question:
I am fairly new to this, so please explain this fairly elementary question.
I am trying to configure squid on XP (squid-2.7.STABLE7-bin) in the following 2 ways. Can I have a sample squid.conf for each configuration
My existing configuration (squid.conf default ) is attached. Please note domains on both the questions are NOT the same – I [...]

Unknown password on Watchguard Firebox X

Question:
I have the serial number, feature key, and live security license
I also have physical access to the appliance
I took over IT for the company but nobody knows the password to this device
Any ideas how I can get in, or will I have to rebuild?
Solution:
There is no password recovery feature on the Firebox. The password is [...]

Unable to change oassword properties in local security policies in Server 2008

Question:
On server 2008, I am logged in as administrator (also tried local domain admin account).  I am trying to edit the domain password policies.  I open the local security policy console via administtrative tools.  Expand security policies -> account policies -> passwork policy.  In right panel, right click minimum password length policy and select properties.  [...]

Static Nat

Question:
Hi,
Remote users accessing the server via vpn connection, but when I do static nat on the outside interface, remote users can not access the server. Could you please tell me if there’s anything I must do.
Solution:
Is the remote VPN subnet  – inclided in your NAT 0 Acess list? id the server on the inside interface, [...]

Windows 2003 Domain Controller and Certificate issue

Question:
Hi ,
I am getting below error, can any help me on this.
Certificate Services denied request 754 because The permissions on the certificate template do not allow the current user to enroll for this type of certificate. 0×80094012 (-2146877422).  The request was for CN=””.  Additional information: Denied by Policy Module
Solution:
Hello Aariz,
Enrol the web server certificate http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_22580689.html
Regards,
PeteLong

How to installl Tripwire on Centos (RHEL)?

Question:
I want to install a IDS for my some server (install Centos), to alert what file is modified…
I know Tripwire but There are not much document of Tripwire
So, how to install and config it?
Or is there other sollution?
Thank you!
Solution:
Hi,
AIDE is for Snort IDS, Nopius is correct need to configure a EPEL repo
Try this Install Steps:
1.      [...]

Why is my cisco client not connecting to ASA 5505: Reason 412: The remote peer is no longer responding

Question:
Hello fellow experts.  I’m stumped on a VPN connection I’m trying to get working with our ASA 5505.  We have our site-to-site VPN connection up and running, its just that the clients connecting with Cisco Client 5.(x) are not able to connect.
First, our client machines are Windows 7 computers running the Cisco VPN Client 5.0.06.0160
We [...]

How to use intrusion prevention system with firewall?

Question:
we are already having 5500 series firewall. we want to add cisco IPS in our system.
IS cisco IPS come with internel firewall? if not how it will stop access of intrusion.
Kindly refer any document that help this kind of general questions about IPS.
Solution:
there’s CSC IPS cards for the 5505 series, or AIP-SSM modules for the [...]