Wednesday, 26 May 2021

cisco ASA FQDNs in a group

ASA needs to be configured to use DNS


dns server-group DefaultDNS

 name-server 8.8.8.8

 name-server 1.1.1.1

 domain-name rn.lgov


object network obj-thulleultinn.club

 fqdn thulleultinn.club


object-group network MALWARE-SOURCES

 network-object host 192.99.178.145

 network-object object obj-thulleultinn.club


Get firepower sensor (sfr) details from ASA CLI

Gives sensor IP and manager IP (FMC)

show modules sfr detail

Thursday, 20 May 2021

cisco asa debug commands for S2S vpn

Set the debug on just your peer

debug crypto condition peer x.x.x.x


Ikev1 / ipsec

debug crypto ikev1 255

debug crypto ipsec 255

ikev2


debug crypto ikev2 protocol 127
debug crypto ikev2 platform 127

Debug crypto ikev2 255

Debug crypto ikev2 platform 255

Debug crypto ikev2 protocol 255


If you need more detail you can enable more

Debug crypto ipsec 255

Debug crypto ike-common 10

Debug crypto engine 255 (causes too much output)


logging console debugging


https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113574-tg-asa-ipsec-ike-debugs-main-00.html#anc6

IKEv2 Notes
IKEv1 had clear phase 1 (ikev1) and phase 2 (ipsec).
IKEv2 does it all in one phase but broken into 3 sections:

IKE_SA_INIT
IKE_AUTH
CHILD_SA


Monday, 17 May 2021

track DNS requests

 

Login to DC

Open DNS

Right click DNS server

  1. Click the Debug Logging tab and check the Log packets for debugging checkbox
  2. To minimize the amount of data being logged, uncheck the following checkboxes:
    • Packet direction - Outgoing
    • Transport protocol - TCP
    • Packet contents - Updates
    • Packet type - Response
  3. In the Log file section, type a path and file name for the log. Alter the Maximum size (bytes) value if necessary.
  4. Click OK.

From:

https://superuser.com/questions/1229515/windows-dns-server-how-to-find-out-who-made-a-query


Now you can search the log with something like this in powershell

get-content dns.log -wait | select-string 'domain1','domain2'


tracking DHCP

C\windows\system32\dhcp\DhcpSrvLog-Mon.log

get-content DhcpSrvLog-Mon.log - wait | select-string 'dell'

Wednesday, 5 May 2021

backup on FMC

link below explaining the backup for FMC and FTD,

https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Backup_and_Restore.html

http://www.network-node.com/blog/2019/3/27/150-copying-backing-up-and-restoring-ftd-device-configuration



Wednesday, 14 April 2021

High unmanaged disk usage on /ngfw cisco FMC/FTD error

After upgrade to 6.7 I got this error in the FMC health section:

High unmanaged disk usage on /ngfw cisco 

Going into the CLI is appeared there was space.
It looks like a bug CSCvc03899. 
Some old install files left behind. 

You need to remove them but you won't be able to roll back to that version. My system was stable and I had taken a backup of the FMC and managed device on 6.7 and no intention to roll back to any previous version anyway.

From CLISH (>) run cleanup-revert
> upgrade cleanup-revert
It is not possible to revert back to the previous version once the revert version is deleted.
Are you sure you want to proceed (yes/no)? yes

Go into expert mode and then (sudo su -)

Find old version files
FTD#cd /ngfw/Volume
# du -hs * | sort -rh
7.3G 6.4.0 ---> old version
6.9G root1
4.1G lib
116K home
0 root

Delete old version files Delete 6.4.0 file as below:
/ngfw/Volume# rm -rf 6.4.0
# du -hs * | sort -rh
6.9G root1
4.1G lib
116K home
0 root

Wednesday, 7 April 2021

FQDN on palo alto firewall

Show all the fqdn's that are resolved

show dns-proxy fqdn all


DNS servers are configured under