Botnet in 5505 ASA v9.2 - Manual entered Blacklist is only Greylisted

Any help is appreciated, I know not a lot of people are running the botnet but after using it on a trial basis I was hooked so I would like to know if this is a but or a setting where blacklisted traffic levels are defined.
I may have had this issue in other versions and not noticed it.
I have two issues, first is manually putting entries into my blacklist section for example:
dynamic-filter blacklist
   name www.sprint.com
Are only being Greylisted so when I test I am still able to get to the webpage because I only block high to very high traffic.
Looking at the monitor it shows that the website was only Greylisted any my filter level was set to only block high and very high threats.
Documentation says manual entries in the blacklist are considered Very High but my system only categorizes them as Greylist.
My current workaround is to go under
Botnet traffic filter
    Traffic Settings
       and select the checkbox for "Treat ambiguous (greylisted) traffic as malicious (blacklisted) traffic
The problem is I may now get false positives.
My other question is can I set the ASA to display a page saying "Blocked by Botnet" or redirect traffic to my internal webserver so I can create that page? Merely blocking a page without definition can cause some frustration.
Can anyone else who has this take a peek to see if this is the same or did I jack one of my settings?
Here is some of my config
threat-detection basic-threat
threat-detection statistics
threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
dynamic-filter updater-client enable
dynamic-filter use-database
dynamic-filter enable interface inside
dynamic-filter enable interface outside
dynamic-filter enable interface dmz
dynamic-filter drop blacklist interface outside threat-level range high very-high
dynamic-filter ambiguous-is-black
dynamic-filter whitelist
name vc.dwwtc.com
address 111.221.77.150 255.255.255.255
address 157.55.177.46 255.255.255.255
name centos.mirrors.hoobly.com
address 66.160.172.98 255.255.255.255
address 69.63.190.0 255.255.255.0
address 205.244.201.221 255.255.255.255
dynamic-filter blacklist
name www.sprint.com

Hello;
That is indeed a feature that we can consider. If you have a Cisco representative, I would strongly suggest you talk to him and request the feature. By now there is no redirect page or block page for botnet.
In regards to the other query. If the site appears to be good on our database, but you categorize is as black, the site would turn out to be grey, the way to drop this would be applying "grey is alway black" which is the option you have.
Mike.

Similar Messages

  • Fixed Asset - Manually enter opening balance

    Hi,
    It's possible to manually enter fixed asset opening balance? anyone wanna share ways of manually enter? l only tried on import way.
    Thanks in advance!
    Phoebe

    Hi,
    There is no feature that can be used to upload FA opening balance amount in the fixed asset addon.
    If you refer to fixed asset master data import, you can use template fixed asset master data to import the master data.
    JimM

  • Manually Enter the Sales Order Schedule Line

    Dear All,
    I have a requirement where Sales Order will be created by Customer Service with Quantity and customer requested delivery date.  Subsequently Planning department will go to the sales order schedule lines and enter manually the delivery date and confirmed quantity (multiple schedule lines) based on the stock/availability.  They also need to do some changes in the shedule line if required.  But when I try, the manually entered schedule lines are disappeared.  Could any one advice how to set this up?
    Thanks,
    Regards,
    Venkat

    Hi Venkat
    A schedule line gets grade out because this has been determined . through schedule line determination. . Now in the shipping data tab you can change the schedule line tab if you want .  manually you can change the request delivery date also. 
    But it is not advisable to change the schedule line because again the affect of availability check will vary.
    But can we know for what purpose you want to change the schedule line when you create the sales order. Any reason .For what purpose you are going for that customization ?For what purpose?
    Regards
    Srinath

  • How to draw custom line in crystal report without manually entering value?

    Hi,
    I have a bubble chart and want to represent custom lines one in x-axis and one in y-axis at the value arrived based upon an internal calculation.There is an option to manually enter value for custom line.
    But i want to generate custom line at runtime without manually entering it.
    Can somebody help out?
    Regards,
    Felix

    Not sure what this has to do with Database Connectivity?
    Moved it to the Report Designer forum. If you are using code then specify what Report engine and version you are using and we can move it again.

  • How can I manually enter MIDI channel number in Control Surface expert Value Change field?

    I am creating a software interface for a multidimensional controller which can transmit many linear values at the same time. I can not use Learn mode because it always sends data from all sources, but I can split them by MIDI channels. I would like to manually enter controlling values into Control Surface expert view.
    I seem to be able only to input the message, but not MIDI channel on which it is transmitted.

    Stupid me, it's hex... so 80 is Note Off ch 1, 90 Note On ch 1 etc

  • Address bar no longer works with manually entered URLs

    Four days ago the address bar stopped working. I am accustomed to manually entering many URLs and hitting 'enter' but although I can still enter URLs as normal, the 'enter' button does not load the relevant page, nor does the green arrow at the end of the address bar do so.

    Create a new profile as a test to check if your current profile is causing the problems.
    See "Basic Troubleshooting: Make a new profile":
    *https://support.mozilla.com/kb/Basic+Troubleshooting#w_8-make-a-new-profile
    There may be extensions and plugins installed by default in a new profile, so check that in "Tools > Add-ons > Extensions & Plugins" in case there are still problems.
    If that new profile works then you can transfer some files from the old profile to that new profile, but be careful not to copy corrupted files.
    See:
    *http://kb.mozillazine.org/Transferring_data_to_a_new_profile_-_Firefox

  • Reset Manually Entered Constrained Forecast Key Figure

    We use Demand Planning to forecast future Sales Volumes.  Not too sophisticated.  We take a monthly extract from R/3 which summarize the last months Sales Actuals.
    based on a given period of Sales History we then run a statistical forecast whicgh generates future months foreasts.
    Once a manual adjustment has been made to a key figure by either Acciount Manager/Marketing Group?Demand Planner, that particular field is highlighted in 'YELLOW'.  Once this is done any future copies of stat numbers into those fields does not overwrite the users manual inputs.  As you would expect.
    However we have some apparently manually entered values in our Constrained Key Figures that are completely incorrect.  However because the cells are yellow, the copy key figure macro will not be able to overwrite these values.  Is ther a way I can somehow reset these yellow cells so that they no longer resist the copying of data into them.
    Apologies if I am using the incorrect terminology here.
    Thanks for anything you can suggest.

    I think your requirement could be met by exploring macro functions CELL_BG(), CELL_FG(), CELL_INPUT(), ROW_BG(), ROW()FG or ROW_INPUT() functions. All the macro functions can be made conditional, example a specific technical/business situation leads to color/editability etc.
    Check http://help.sap.com/saphelp_scm2007/helpdata/en/17/a5216532a111d398260000e8a49608/frameset.htm

  • How to use the manually entered Hours/Days in the Duration field for BG_ABSENCE_DURATION

    Hi All,
    How to use the manually entered Hours/Days in the Duration field for BG_ABSENCE_DURATION fast formula?
    Requirement is to restrict employees for applying for leave more than the accrued balance. In SSHR, apply leave functionality, the employee enters the start date, end date and duration manually. The entered duration must be used in the fast formula to check against available balance.
    In the BG_ABSENCE_DURATION FF, I have a function to calculate the net accrual balance as on the calculation date.
    I want to add the logic as - If to_number(Duration) /*[manually entered value]*/ > net accrual balance then
    Duration = 'FAILED'
    invalid_msg = 'Error'
    return duration, invalid_msg
    Thanks!

    Hi,
    We have a standard functionality to override the duration calculation and you don't need to add a validation for the same. Please set the value of profile option HR: Absence Duration Auto Overwrite to Yes
    When you do this user will not have to enter the duration value manually. It will get auto calculated based on the duration calculation in BG_ABSENCE_DURATION when you click on the next button.
    For not allowing negative leaves to be applied, If you are on R12 then, this is a standard functionality and you need to set profile option HR Allow Absence Negative Balance to No
    If you are on 11i then refer Note: 268171.1: How Do You Stop Accrual Plans from Going Negative?
    Try and let me know in case you need further help.
    Thanks,
    Sanjay

  • I'm among about 140 people who received the same email. I want to include all of those addresses in a new group. Is it possible to create the group without having to manually enter each of the 140 addresses?

    I'm among about 140 people who received the same email. How can I create a new group for these people without manually entering all 140 addresses?

    Hi  SDGNOM,
    According to your description, my understanding is that you want to export  list to Excel with all columns in your SharePoint.
    For the SharePoint RPC protocol method, SharePoint export to excel will take the list id as well as the view id. So we cannot export list to Excel with all the columns without having to depend on the fields
    chosen in the default view.
    Reference:http://msdn.microsoft.com/en-us/library/ms478653.aspx
    For a workaround, you can achieve your demand via PowerShell. Here is a  template you can refer to:
    Param(
    [Parameter(Mandatory=$True)]
    [string]$webUrl,
    [Parameter(Mandatory=$True)]
    [string]$outPath
    $web = Get-SPWeb $webUrl
    write-host ("Path: " + $outPath)
    foreach($list in $web.Lists)
    $exportlist = $null
    $exportlist = @()
    $list.Items | foreach {
    $hash = $null
    $hash = @{}
    foreach($fld in $_.Fields ){
    Try {
    $hash.add($fld.Title, $_[$fld.Title])
    Catch [System.Management.Automation.MethodInvocationException]
    # Eating an error caused by duplicate column names.
    Finally
    #"End"
    write-host ("Exported: " + $_.Title)
    $obj = New-Object PSObject -Property $hash #@{
    $exportlist += $obj
    $expath = $outPath + '\' + $list.Title + '.csv'
    $exportlist | Export-Csv -path $expath #$oPath
    Reference:
    http://porchcode.blogspot.com/2013/04/exporting-sharepoint-list-items-to-csv.html
    Thanks,
    Eric
    Forum Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support,
    contact [email protected]
    Eric Tao
    TechNet Community Support

  • Can I get my iCloud keychain PW so that I can manually enter it?

    iCloud Keychain created a PW for me to use to create an account with an ISP.
    I would like to login to the account using my email account and PW using a shell session, but I need the PW which is kept by iCloud Keychain.
    Is there any way I can access this PW and manually enter it during my shell session?
    Thank you.

    Click launchpad, click the "Other" icon on the apps list. Click keychain access. You can search for all sites that have passwords stored for them. Double click on the website your looking for click the Show Password check box, enter your admin password and click allow. There is the password in question, I believe you are searching for.
    Keep in mind you may have to select the Password option in the left menu pane under category before your search.
    HTH. Cheer

  • How do I manually enter a location for photos in Photos app?

    I had just started to use the old iPhoto but then came the update to Photos app. I used to be able to manually enter location for some of my photos in the iPhoto app. How can I do the same with the new Photos app? Since this is an update, surely there must be a better way or improved interface to do the same!

    Unfortunately they have not included this feature in the new Photos app.
    Send feedback:
    https://www.apple.com/feedback/

  • Payment Method while manually entering Receipt

    Hi,
    I am not getting any payment method in the LOV for Payment Method while manually entering the receipt information. Receipt class and Payment method is defined in the system.
    Do I need to do any other setting so that the defined Payment method will be available in the LOV.
    Please help.
    Thanks,
    Girish

    Hi,
    I dont have any bank details associated with the receipt class. Is is mandatory?
    when I am trying to link some bank details to this class then I am not getting any values on the LOV for "Unearned Discounts" and "Earned Discounts" fields.
    Please suggest.
    Thanks.

  • Ecatt vs. Manually entered transactions

    Hello
    We are currently performance testing and we are thus creating a lot of transactions using eCATT - e.g VA01.
    My question is now: why is there a difference in response time when creating one VA01 with the eCATT and creating one VA01 manually (with exactly the same line items, customer etc.)?
    And finally: is there a ratio that we can apply to compare eCATT generated VA01s with manually entered VA01s?
    Thank you very much.
    Cheers
    Tajs

    Hi,
    ECATT is a automation tool meant for functional testing in SAP. It comes with WAS.
    QTP tool which is a third party tool for automation testing. The language used here is VB Script.
    The only drawback with ECATT as of now is that it can execute web based SAP transactions except WebDynpro.
    If the testing of SRM, CRM etc is involved, one is forced to use QTP.
    QTP takes the wrapping of ECATT and executes in SAP.
    SAPGUI based transactions are involved in testing than ECATT is the best tool to be used.
    And if web based transactions are also involved, forced to go for QTP.
    I think it would help you to some extent
    Edited by: Vagdevi on May 18, 2009 5:48 PM
    Regards
    R
    Edited by: Vagdevi on May 18, 2009 5:48 PM

  • Manually Entering Primary Key.

    Hi,
    I am in the very early stages of looking at creating Apex Forms/Reports to replace our existing systems on Oracle Forms.
    In the existing database, there are huge numbers of tables that use manually enterable primary keys when creating the record.
    These primary keys can be very simple, such as just a 6 character code field or 20 character reference field (made up of several different user enterable fields concatenated together) to multiple composiite primary keys, where there could be several levels of master/detail records.
    I have looked in the forums for information on this but am struggling to find a way of being able to create records where the primary key can be typed in manually when inserting records and then getting the reports/forms to work. I do not need to update the primary key, just allow it to be entered.
    It would just not be practical to create new sequences as primary keys for all our tables, just to get Apex to work how it wants - wouldn't this mean dropping the existig PK and creating a new one, then populating all records with the new sequence?
    I need to be able to use tabular forms for multi row record inserts where the user can enter (but not modify) the PK - using a report/form to do this seems too long winded. I will also need to be able to do this in a form only, for inserting singular records.
    Any help would be appreciated.
    Regards,
    Carl

    you should set in your entity object the attribute as DBSequence and then create a before insert trigger in the db table to get the pk from a sequence or so, something like:
    CREATE OR REPLACE TRIGGER trigger_name
    BEFORE INSERT
    ON table_name
    FOR EACH ROW
    begin
    select seq_name.nextval into :new.pk_id from dual;
    end;

  • Manually Entering Segment

    Hi,
    I have created 4 segments:
    SBU1
    SBU2
    SBU3
    SBU4
    I have created 3 Profit Centers
    PC01
    PC02
    PC03
    Now in the above scenario, the client wants
    SBU1 >>> PC01 and PC02
    SBU2 >>> PC01 and PC03
    SBU3 >>> PC02 and PC03
    SBU4 >>> PC01 / PC02 / PC03
    If I do not maintain any segment in the above 3 Profit Centers Master Data, is it possible to manually enter the segment while posting an entry in the system?
    NO NEW GENERAL LEDGER / DOCUMENT SPLITTING IS CONFIGURED IN THE CLIENT SYSTEM
    Please assist on the same.

    Hi
    You have the choice to derive Segment
    1. From Profit Center Master
    2, Write your own logic in Badi FAGL_DERIVE_SEGMENT
    3. Enter segment manually at each transaction.
    Regards
    Sanil Bhandari

Maybe you are looking for

  • Can't get adobe downloads in foxfire 5.0.1

    I am on 3.6.19 Foxfire. I CAN get downloads of financial statements.When I switched to 5, then 6 beta, I could no longer get downloads from them. I went back to 3.6.19 and I can can them. I keep getting notices to go to 5. so I tried it and adobe wou

  • Inserting Multiple Rows into Database Table using JDBC Adapter - Efficiency

    I need to insert multiple rows into a database table using the JDBC adapter (receiver). I understand the traditional way of repeating the statement multiple times, each having its <access> element. However, I am just wondering whether this might be p

  • ABAP Objects issue

    when calling to method in abap objects we can write CALL METHOD method_name              EXPORTING               param =: value1 , value2 , .... ,valuen . but how can i call method if it get 2 parameters ? means like CALL METHOD method_name          

  • Need Help With Capturing EDirectory/IChain User Info

    After 8 years, we were finally able to get our production ColdFusion MX7 server, working with the company's EDirectory server.  EDirectory now authenticates users, based on their job title, job class, job group, etc.  We provided our IS (Information

  • Lightroom 2 Catalog Previews.lrdata?

    I am running into space problems on my C drive (hard to imagine, but I my computer was configured before LR and iTunes).  I have moved the iTunes music to another drive, but still need to free up space.  LR is using over 3GB in the following location