Fortinet – Common PCI/Security audit issues

Fortinet – Common PCI/Security audit issues Leave a commentPosted by cjcott01 on December 29, 2016 This is an ongoing blog, and one that I will update often will things that come up in security audits. Companies are always getting external audits to make sure they comply with policies and have no outstanding vulnerabilities with their systems. This is great, … Continue reading Fortinet – Common PCI/Security audit issues

Advertisement

Troubleshooting Cisco VPN Phase 2

Problem It’s been over two years since I wrote Troubleshooting Phase 1 Cisco Site to Site (L2L) VPN Tunnels. I’ve always meant to come back and write the ‘Phase 2’ article but never got around to it. This article is NOT intended to be a ‘fix all” for phase 2 problems, it’s designed to point you in the … Continue reading Troubleshooting Cisco VPN Phase 2

Troubleshooting Cisco VPN Phase 1

Problem Site to Site VPN’s either work faultlessly straight away, or involve head scratching and a call to Cisco TAC, or someone like me to come and take a look. If I’m honest, the simplest and best answer to the problem is “Remove the Tunnel from both ends and put it back again”. Just about every VPN tunnel … Continue reading Troubleshooting Cisco VPN Phase 1

Useful Cisco Site-to-Site VPN Phase 1 and 2 Status Troubleshooting Commands

One way is to display it with the specific peer ip. Check Phase 1 Tunnel ASA#show crypto isakmp sa detail | b [peer IP add] Check Phase 2 Tunnel ASA#show crypto ipsec sa peer [peer IP add] Display the PSK ASA#more system:running-config | b tunnel-group [peer IP add] Display Uptime, etc. ASA#sh vpn-sessiondb detail l2l … Continue reading Useful Cisco Site-to-Site VPN Phase 1 and 2 Status Troubleshooting Commands

Tricks: Unable to access Sonicwall Management Portal? ERR_SSL_VERSION_OR_CIPHER_MISMATCH

Most modern web browser no longer support RC4 encrytion as it is officially declared unsecured by IETF memo RFC7465 published on February 2015. (See Workaround below to find an older browser to get around this error) Thus if RC4-Only encryption is enabled in SonicOS, it would block access to the Firewall Management Portal and will display "err_ssl_version_or_cipher_mismatch" error … Continue reading Tricks: Unable to access Sonicwall Management Portal? ERR_SSL_VERSION_OR_CIPHER_MISMATCH

Tricks: Introducing Cisco RF Planning Tool

Here is a useful planning tool in Wireless Network provisioning for Cisco Meraki AP or the Mobility Express models. This is an online tool called Cisco RF Wi-Fi Planner Tool. Check out https://rftool.cisco.com You can use this by logging in to your Cisco Account. You can put into account external factors in designing your wireless network … Continue reading Tricks: Introducing Cisco RF Planning Tool