Just about any IOS version you can sucessfully run on the 3620's and 3640's should be able to perform the shunning capability. The 4210 will telnet or ssh into your router and CLI configure a temporary ACL to shun each attacker (IP or port) for each signature that fires that you have set the action to "shun".