Cisco ASA – Only Allow Mail Servers SMTP Outbound
Nov17

Cisco ASA – Only Allow Mail Servers SMTP Outbound

KB ID 0000172  Problem It’s not unusual for nasty Virus’s and Malware once they have infected a machine, to set up outbound communications on the mail protocol SMTP (TCP Port 25), which can lead to your public address being blacklisted. So it’s considered good practice to stop all your clients getting mail access outbound through your firewall, while still allowing your mail server. Note: On Cisco firewall’s,...

Read More
Securing Cisco SSL VPN’s with Certificates
Nov17

Securing Cisco SSL VPN’s with Certificates

KB ID 0000335 Problem It’s been a while since I wrote a walk though on the Cisco AnyConnect/SSL VPN solution, and usually I secure these with Active Directory or simply using the local user database on the firewall. But what if you wanted to use certificates instead? Perhaps your users are too “technically challenged” to remember their passwords. Or you want to enable two factor authentication with...

Read More
Cisco ASA – Enrolling for Certificates with NDES
Nov17

Cisco ASA – Enrolling for Certificates with NDES

KB ID 0000948 Problem To get your ASA 5500 firewall to enroll, and obtain a certificate from a Windows Server running NDES, this is the procedure you need to follow. Solution When dealing with certificates, it’s important that your firewall is maintaining the correct time. You can set this manually, but I’d recommend setting up NTP. Cisco ASA – Configuring for NTP 1. Make sure the firewall can contact the NDES...

Read More