Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Blocking with version 4.0

I while back I asked if you could block directly from the sensor in version 4 without VMS or CSPM - and was told you cannot - however further reading leads me to beleive that you can block without a separate management console - can anyone verify this for me.

Which leads me to my next question - can it send email alerts without a separate management console.

Thanks in advance.

Heath

  • Other Security Subjects
1 REPLY
Cisco Employee

Re: Blocking with version 4.0

Hi Heath,

The blocking / shunning is a function of the sensor. so this can be configured on the sensor using the CLI. If you get into the "service NetworkAccess" configuration, you will see all the aprameters that are required to setup shunning.

The CLI for 4.x is documented here

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids9/cmdref/15285ch2.htm

On the other hand, the email notification is a function of the Security Monitor and not that of the sensor, hence email alerts can be sent only via the Security Monitor which is part of the VMS. CSPM is out of question as it does not support the newer version, 4.x, of the sensors.

Hope this helps,

Thanks,

yatin

87
Views
5
Helpful
1
Replies