Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Shun in both directions

When a master blocking sensor issues a shun to a pix it shuns x.x.x.x / 0.0.0.0 which will block any host with address x.x.x.x making a connection to your PIX. However if we take the case of an IE exploit you want the SIG to fire and the shun to block x.x.x.x / 0.0.0.0 AND 0.0.0.0 / x.x.x.x so that further attempts by internal systems to access the malicious site are blocked. At the moment the shun is ineffective for this type of threat, is there any way to make it work both ways shunning connections from and to the host?

1 REPLY
Silver

Re: Shun in both directions

You might be able to accomplish this through the Swap Attacker Victim parameter on many IPS signatures. Just clone the sig you want to fire and set the Swap Attacker Victim parameter to 'Yes'. This may do it..

145
Views
4
Helpful
1
Replies
CreatePlease to create content