Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IDS: Blocking Lasts Longer than Setting

IDS 4210 v3.1

PIX 515 v6.2(2)

Blocking (shunning) is configured via IDM and set at default of 15 minutes.

Been working fine so far.

Just checked my PIX and saw that a shun was entered and has lasted over 16 hours.

Whassup with that?

Tony

  • Other Security Subjects
1 REPLY
Cisco Employee

Re: IDS: Blocking Lasts Longer than Setting

If the sensor continuously sees the same alert coming from the same host, and that alert is set up to be blocked, then it'll keep adding the shun command to the PIX constantly, that could be why you're seeing it in there for so long.

Check your IDS logs, do they show a number of alerts from this shunned host, and do you see that number of alerts incrementing steadily?

You can also check the /usr/nr/var/log.$DATETIME and search for "shun" entries, this'll tell you how often the sensor has shunned that host on the PIX. If you see regular shun entries then that'd explain it. If you see only one then that shun entry has probably gotten stuck, perhaps the sensor lost connectivity with the PIX 15 hours and 45 minutes ago and the entry has been left there.

96
Views
0
Helpful
1
Replies
This widget could not be displayed.