Hello! Appreciate this series of videos! I do have a question that doesn't seem to be covered. On our FW, we have multiple Connection Profiles with associated Group Policies. We'd like to be able to control access so that, for example, a user that is a member of a particular AD group can ONLY log in to a particular Connection Profile on the FW. (Or possibly more than one. (depending on how many AD groups they are members of....) The point is that if a user is a member of Groups A and B (but not C) within AD, then on the FW they'll be able to connect on VPN to GRoups A and B, but not C. Is one or more of these flows best for that requirement? If more than one, which would you recommend as being best for not losing other capabilities (e.g., HA)? I am considering implementing ISE (instead of our current NPS), and wondering how best to implement it. Thank you!
@rashedenab4317 күн бұрын
We are using cisco Umbrella in our environment. And I decided to share you some questions I have in mind Now, In the Umbrella Dashboard there are two tabs , one is called External Domains , which inspects the DNS traffic for the clients going to the listed domain and DO NOT inspect web traffic We add domains for websites that drops http/s connections from a proxy , somehow they detect it We also have another list called selective decryption list , the inspects DNS traffic , also web traffic , BUT DO NOT PERFORM deep inspection because the server somehow knows that the traffic is being read by an intermediate which is the Umbrella proxy. My question is , what if a user faced an issue with a domain or website because of Umbrella, how I can know where to add it first ? Any browser error indicates the cause? Thanks for the great content!
@NetworkWizkid5 күн бұрын
Thank you for watching. You can identify the rules that a affecting a user. Please take a look at the Cisco Umbrella documentation or go through this training which covers how you can find the policy. You can find the training here: networkwizkid.com/free-cisco-umbrella-course/
@rashedenab4314 күн бұрын
@@NetworkWizkid Thanks , Any plans to make a course on Cisco Meraki ?
@1habeel12 күн бұрын
Hey! Im quite done with my security just gonna get done with ISE in a couple of days, what software are you using here? Im on eve-ng, i wanted to ask which one are you using?
@NetworkWizkid5 күн бұрын
I use a mix of virtual and physical software and nested EVE-NG within a virtual environment.
@MrKashifiq16 күн бұрын
First of thanks for sharing such a good video. I have found only 3 videos on NGIPS. Is there any other videos related with Cisco NGIPS or not? Regards
@NetworkWizkid5 күн бұрын
Thank you - I will be bringing some new content shortly. Keep notifications turned on so that you'll be notified when I release new content.
@itsame847023 күн бұрын
This is a great set of videos. Best ones on the topic. How would you handle your internal and external domains being the same? I can't find an answer to this. Our vendor changed networks and the proxy's public IP and now the website shows insecure. I've already had Cisco tell me that it's configured correctly. Is it because they're using the shortened domain version on the website?
@NetworkWizkid5 күн бұрын
To answer your first question, you either have Umbrella handle the DNS resolution or not. Without knowing the network and setup it difficult to answer the second question but I would speak to your vendor of Cisco support if you have any issues. Thank you for watching and I'm glad that you found these videos useful.
@trustprise24 күн бұрын
No one link works get message: We couldn't find the resource you're looking for. The course you're looking for may already be retired or obsolete. Try a new search or view available content for a subscription homepage. Go home
@InfoTech_SiteАй бұрын
I have just passed the CC exam. Your video helped me a lot, followed the information you have provided. I have collected the most important questions from my preparation and created a video series on the CC exam with important questions here: kzbin.info/www/bejne/l5infIGmrt-sj8k
@NetworkWizkid5 күн бұрын
Thank you - I am glad this helped you pass and congratulations
@alifarsani2469Ай бұрын
it gives me error and does not like anything in the code
@metalsnake00Ай бұрын
why da hell will you get this if Microsoft have it all by there license
@funmemes59152 ай бұрын
Thanks, this work to me
@NetworkWizkid2 ай бұрын
Great! Thanks for watching.
@cezarkrs72872 ай бұрын
Everything will be more expensive this way including plumbers,electrician,taxi,etc. They will have to put this expense on your bill. A flat rate for vehicles with £0 road tax would work better.
@gabrielgarcia-xo5xy2 ай бұрын
Why was authentication failing even with 'open authentication' configured for that switchport?
@NetworkWizkid2 ай бұрын
Because there was no policy in place on ISE.
@gabrielgarcia-xo5xy2 ай бұрын
nvm I guess my question is, even though it's showing that it is failing... 'open authentication mode' allows the device to still access the network?
@NetworkWizkid2 ай бұрын
Correct
@mohammadaminulislam55582 ай бұрын
Video quality is not so good
@NetworkWizkid2 ай бұрын
Looks ok to me. Have you tried changing the video quality settings to 1080?
@rashedenab4312 ай бұрын
Studying on the CCNP security , this series is a banger , can't thank you enough for this you are a legend. btw , I'm thinking on obtaining the CCNP ISE , is it covered here ? and what do you think of the specialization? Again , you are a living legend
@rashedenab4312 ай бұрын
Also , would it be okay to explain the GRE over IPsec ?
@NetworkWizkid2 ай бұрын
Thank you for those kind words and thanks for watching. I do have some ISE content on here and will also be delivering more soon.
@NetworkWizkid2 ай бұрын
If I remember, I will try and cover it in a video
@rashedenab4312 ай бұрын
@@NetworkWizkidlooking forward to it!!
@Nezar0712 ай бұрын
What if i have two ISE nodes setup, do i need to integrate both to Azure AD ?
@NetworkWizkid2 ай бұрын
I'm assuming you are referring to a distributed deployment where you have x2 PANs?
@SurajSingh-o5i9s2 ай бұрын
Congratulations bro 🎉🎉
@NetworkWizkid2 ай бұрын
Thanks 🔥
@mohamedmowafy19083 ай бұрын
Thanks 👍
@NetworkWizkid3 ай бұрын
No problem, thank you for watching
@jjcrips49283 ай бұрын
Question: I have 2 VA's that were being used with a dashboard with an existing ISP. Since then, we have gone with a new ISP and part of the package of using it, we get Umbrella. With that being said, the old dashboard is no longer available. The new dashboard did not automatically populate / show the existing VA's even though they are working just fine. How do I get these existing VA's that were in the old dashboard (no longer available) to show in the new dashboard? Do they need to be re-registered or??? I appreciate any insight you can give me in advance. Thanks.
@NetworkWizkid3 ай бұрын
It sounds like you've got a new Umbrella tenant based on the new subscription. If that is the case, configuration from previous tenants are not transferrable and therefore that's why you cannot see the old VAs. The old VAs should be removed and you should configure new VAs for the new Umbrella subscription. I hope that provides some more clarity and thanks for watching.
@jjcrips49283 ай бұрын
Thanks for the response! Appreciate your time! Standing up new ones today!!
@antster73 ай бұрын
Can't you federate directly to Duo?
@NetworkWizkid3 ай бұрын
Duo isn't an IdP
@drifm4niac6623 ай бұрын
Nonsense the public transport it’s already overcrowded, this will only decrease the quality average life of the people ! And talking about funding if the government cared ,thy wouldn’t be sending money abroad to support wars and would instead focus on our country and our problems . Thoughts this was the whole point in the nonsense of leaving eu and making my shopping go from 250£ to 600£ 👏🏽
@sinade13 ай бұрын
This is informative. Thank you.
@NetworkWizkid3 ай бұрын
Glad it was helpful! Thank you.
@jonc53733 ай бұрын
Yes my brother. That really helped. liked and subscribed
@NetworkWizkid3 ай бұрын
Awesome, thank you and thanks for the sub!
@sleepyrasta4203 ай бұрын
I won't be paying per mile I'll just take the plate off my bike
@bolatan113 ай бұрын
Do you have the asa 9.0(4) image
@NetworkWizkid3 ай бұрын
Sorry, it's not permitted to share images. If you require the image, then please access software.cisco.com with a valid account that is capable of downloading software.
@bolatan113 ай бұрын
@@NetworkWizkid I know but the image is no longer on the cisco site as it is no longer supported
@NetworkWizkid3 ай бұрын
@@bolatan11 I see! I don't save the images unfortunately, sorry.
@NetworkWizkid3 ай бұрын
This tool has now been updated and includes 3 different options now.
@gavinbissell88473 ай бұрын
Looks like she needs the exercise
@aydnmahmudov67393 ай бұрын
Perfect worked for me on esxi 8.0. Thanks a LOT.
@NetworkWizkid3 ай бұрын
Good to hear, thank you for watching
@MarioRavellino3 ай бұрын
You're the master
@NetworkWizkid3 ай бұрын
Appreciate that, thank you :-)
@kutalanota21223 ай бұрын
Thanks for sharing as always and welcome back!!!
@NetworkWizkid3 ай бұрын
No problem and thank you...I had to recharge!!
@brambles00777777773 ай бұрын
Tax the drivers of the Q5's and X5's etc a fortune and make driving one up in a Chelsea tractor a premium cost.
@shaicruz1763 ай бұрын
I already pay per mile it’s called fuel duty. The more you drive the more you will pay. I will not comply to this law it’s inhumane.
@andrewstevens60053 ай бұрын
More ways of scamming drivers out of our hard earned money!
@dw55513 ай бұрын
Only hits the poor though. Rich will just keep driving.
@connorboyd66763 ай бұрын
So I gotta pay mandatory insurance, road tax, mot fees & this? I’m better off getting the bus
@ElenEmma883 ай бұрын
@@connorboyd6676 that’s what they want u to do ;)
@debeightonethree63463 ай бұрын
Pay per mile? Mate- that’s petrol. STFU with this.
@jamiearmstrong-vi9om3 ай бұрын
These "schemes" are not only unnecessary, they have virtually no support. Essentialy poorest are hardest hit....again
@NetworkWizkid3 ай бұрын
I think it's a ridiculous proposal - just another way to further tax motorists!
@Abdullah_khan3334 ай бұрын
brilliant... 👍👍
@NetworkWizkid4 ай бұрын
Thanks a lot 😊
@AlpiFirat4 ай бұрын
I dont have that cover thing for my Max hero 8. What Do I have to do?
@NetworkWizkid4 ай бұрын
Take a look at your manufacturers guide and they should highlight the correct process.
@josephcooper58884 ай бұрын
Hello Kelvin My name is Joseph Cooper I wanted to know how to I go about restricting Remote vpn client user to only access a specific server on the DMZ. They are successfully connect to the vpn but I want to limit 1 server to one client and not the entire subnet.
@ImEddieful4 ай бұрын
Would an older CISSP book covering the exam in 2021 or 2022 help? I have some free audiobook options for those.
@NetworkWizkid4 ай бұрын
For the CC it would help, yes. Take a look at my other video where I map the CC domains to the CISSP: kzbin.info/www/bejne/bH7Rqn2qiqt5oNE&ab_channel=NetworkWizkid
@nurmahmud99064 ай бұрын
Nice
@mjsharmo79134 ай бұрын
We currently have a multi tenant setup where our logins have multiple organisations underneath. How does this SSO translate to accounts below our master account?
@JankaFujkova5 ай бұрын
Google
@JankaFujkova5 ай бұрын
Google
@bongji-p8t5 ай бұрын
under external authentication will it show two profiles
@ricardovarela85475 ай бұрын
Great explanation, I was having trouble with the zones but you clarified it as a pro. Thx
@NetworkWizkid5 ай бұрын
Glad it helped!
@familyandgoodtimes63765 ай бұрын
Writing next week, keeping fingers crossed.
@NetworkWizkid5 ай бұрын
How did you do?
@marcblount796 ай бұрын
Great video, thanks! I have gone through this setup but on the latest SFMC and FTD versions (7.3.1), same steps but interface is different. I got it to work as per your video but the BVI needs an IP in the same range, taking this away stops the bridging. I am looking for a solution where the outside network IP will change (its a mobile office), so was hoping to not have to reconfigure FTD each time IP/site changes. cheers
@samueldelacruzvalenzuela6656 ай бұрын
Excellent Video!
@NetworkWizkid6 ай бұрын
Thank you very much!
@tpatch39716 ай бұрын
Thank you so much, right to the point. This is going to help me soo much.