06-06-2014 02:41 AM - edited 03-11-2019 09:18 PM
Is there a limit to the number of shuns configured on an interface of a Cisco ASA 5550 with 8.4.3?
Solved! Go to Solution.
06-06-2014 08:26 PM
hi,
it's not a limit to the ASA's interface per se. only a single shun entry can exist for any one source host at any time.
if you shun a single connection and the host launches an attack from a different source port, the shun would have no effect on that subsequent attack.
you cannot add multiple shun entries for the same host.
06-06-2014 04:52 AM
I don't believe there is a limit as to how many shun entries you can configure, with the exception that you can only have a single shun entry for a given source address. But you may be limited by the CPU performance of your ASA depending on how much traffic is being dropped. So that being said I would try to keep the amount of shunned IPs to a minimum.
--
Please remember to select a correct answer and rate helpful posts
06-06-2014 08:26 PM
hi,
it's not a limit to the ASA's interface per se. only a single shun entry can exist for any one source host at any time.
if you shun a single connection and the host launches an attack from a different source port, the shun would have no effect on that subsequent attack.
you cannot add multiple shun entries for the same host.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide