The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About LucasDelmarcel
LucasDelmarcel

LucasDelmarcel

Conversationalist

Member since Aug 5, 2021

‎12-17-2021
Kudos given to
User Count
IT_Magician
IT_Magician
1
View All

Community Record

2
Posts
0
Kudos
0
Solutions

Badges

Lift-Off View All
Latest Contributions by LucasDelmarcel
  • Topics LucasDelmarcel has Participated In
  • Latest Contributions by LucasDelmarcel

Re: Log4J detection

by LucasDelmarcel in Security / SD-WAN
‎12-13-2021 01:30 PM
‎12-13-2021 01:30 PM
Correct. You should make an inventory to assess what is running vulnerable versions of software. I use Metasploit vulnerability scanner for this. Stay safe ! ... View more

Re: Log4J detection

by LucasDelmarcel in Security / SD-WAN
‎12-13-2021 05:55 AM
‎12-13-2021 05:55 AM
Hi community, we have this issue currently investigated (not with Cisco, but internally as we are a Cisco partner) Meraki MX uses the same kind of security intelligence sources as lets say an FTD  (Cisco Thalos, Snort,etc,..) , and after discussed this with our senior engineers we believe Meraki firewalls should have the latest updates installed and so the latest Snort-definitions. See this for reference https://www.snort.org/advisories/talos-rules-2021-12-11 It doesn't seem SSL inspection is necessary, but layer 7 application-based policy should do for IPS.   Also, I would personally recommend to restrict LDAP, DNS traffic to a bare minimum so it's tightened to what you really need (ex: DNS-server can reach outside, but rest of the network is more limited) General security advisory..   Hope this helps   Kind regards ... View more
Kudos given to
User Count
IT_Magician
IT_Magician
1
View All
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2022 Meraki