×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Shun in both directions

Unanswered Question
Mar 31st, 2006
User Badges:

When a master blocking sensor issues a shun to a pix it shuns x.x.x.x / 0.0.0.0 which will block any host with address x.x.x.x making a connection to your PIX. However if we take the case of an IE exploit you want the SIG to fire and the shun to block x.x.x.x / 0.0.0.0 AND 0.0.0.0 / x.x.x.x so that further attempts by internal systems to access the malicious site are blocked. At the moment the shun is ineffective for this type of threat, is there any way to make it work both ways shunning connections from and to the host?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (1 ratings)
Loading.

Actions

This Discussion