Re: [OSL | CCIE_Security] IOS IPS bypassed

2012-05-09 Thread Kamran Shakil
It seems the signatures were not properly loaded and compiled,activated ! Check the commands. Kamran Shakil Technical Consultant P.O. Box: 198 Ruwi - Postal Code : 112 , Muscat , Oman T: +968 2416 F: +968 2416 1100 M: +968 9808 4652 E-mail: kamran.sha...@mds.com.om MDS Oman is a

[OSL | CCIE_Security] Configuring basic LDAP support

2012-05-09 Thread Ben Shaw
Hi All I am going through the ACS/Identity Management section of the expanded blueprint and in point 5.07 it lists Configuring Basic LDAP Support. I am wondering if this means getting ACS to integreate with a generic LDAP server or more specifically integrating with Microsoft Active Directory.

Re: [OSL | CCIE_Security] Configuring basic LDAP support

2012-05-09 Thread Kingsley Charles
Just know, how to configure ACS and ASA for LDAP with parameters like base-db, group-base-dn,login parameters, object class and naming attributes. With regards Kings On Wed, May 9, 2012 at 8:26 PM, Ben Shaw veeduby...@gmail.com wrote: Hi All I am going through the ACS/Identity Management

[OSL | CCIE_Security] DMVPN over GETVPN with multicast rekey/Different server than the Hub.

2012-05-09 Thread Mike Rojas
Hi, I was doing lab 17 IPexpert. I did the configuration accordingly and I tried to apply the crypto map for GETVPN on the same interface as the tunnel interface on the spokes. Now, checking the solution, I dont see where they applied the crypto map for the GETVPN. Another thing that

[OSL | CCIE_Security] FW: DMVPN over GETVPN with multicast rekey/Different server than the Hub.

2012-05-09 Thread Mike Rojas
Ohh Another question, it did said something about to not encrypt the multicast rekey and they created an ACL on the spkes and applied a Match address. Would it make any difference if I applied the denies for the multicast address on the same IPsec rule as the one that is pushed from the KS?