When a master blocking sensor issues a shun to a pix it shuns x.x.x.x / 0.0.0.0 which will block any host with address x.x.x.x making a connection to your PIX. However if we take the case of an IE exploit you want the SIG to fire and the shun to block x.x.x.x / 0.0.0.0 AND 0.0.0.0 / x.x.x.x so that further attempts by internal systems to access the malicious site are blocked. At the moment the shun is ineffective for this type of threat, is there any way to make it work both ways shunning connections from and to the host?