cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
505
Views
5
Helpful
1
Replies

IDS PIX shunning

rolalo
Level 1
Level 1

How do i configure the PIX for IP blocking when my IDS detect an anomalous activity?

My IDS version is 3.0(1)S4

I have a CSPM version 2.3.3i

1 Accepted Solution

Accepted Solutions

gfullage
Cisco Employee
Cisco Employee

You don't really configure the PIX, you just need to configure the sensor (via CSPM) to do blocking. When the sensor detects a signature that is set up for blocking, it will telnet/SSH to the PIX and add a "shun" command that will drop all packets from the signature source.

http://www.cisco.com/univercd/cc/td/doc/product/ismg/policy/ver23i/idsguide/ch03.htm#57747

Noe that for a PIX, there is no interface to apply this to, the shun get's applied to all incoming packets on all interfaces.

You then need to modify the particular signature so that one of it's Actions is to block.

http://www.cisco.com/univercd/cc/td/doc/product/ismg/policy/ver23i/idsguide/ch05.htm#xtocid263714

BTW, I would seriously consider upgrading your signatures, you are about 25 signatures releases and 4 service packs behind now.

View solution in original post

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

You don't really configure the PIX, you just need to configure the sensor (via CSPM) to do blocking. When the sensor detects a signature that is set up for blocking, it will telnet/SSH to the PIX and add a "shun" command that will drop all packets from the signature source.

http://www.cisco.com/univercd/cc/td/doc/product/ismg/policy/ver23i/idsguide/ch03.htm#57747

Noe that for a PIX, there is no interface to apply this to, the shun get's applied to all incoming packets on all interfaces.

You then need to modify the particular signature so that one of it's Actions is to block.

http://www.cisco.com/univercd/cc/td/doc/product/ismg/policy/ver23i/idsguide/ch05.htm#xtocid263714

BTW, I would seriously consider upgrading your signatures, you are about 25 signatures releases and 4 service packs behind now.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card