cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
306
Views
4
Helpful
1
Replies

Shun in both directions

d-g-c
Level 1
Level 1

When a master blocking sensor issues a shun to a pix it shuns x.x.x.x / 0.0.0.0 which will block any host with address x.x.x.x making a connection to your PIX. However if we take the case of an IE exploit you want the SIG to fire and the shun to block x.x.x.x / 0.0.0.0 AND 0.0.0.0 / x.x.x.x so that further attempts by internal systems to access the malicious site are blocked. At the moment the shun is ineffective for this type of threat, is there any way to make it work both ways shunning connections from and to the host?

1 Reply 1

jwalker
Level 3
Level 3

You might be able to accomplish this through the Swap Attacker Victim parameter on many IPS signatures. Just clone the sig you want to fire and set the Swap Attacker Victim parameter to 'Yes'. This may do it..

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card