Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 

F5 Remediation Module and Documentation

Allows Sourcefire to pass event details to F5's BigIP.  Big IP can insert an iRule to block or quarantine a device.

Version history
Revision #:
1 of 1
Last update:
‎07-21-2014 12:17 PM
Updated by:
 
Labels (1)
Attachments
Comments
Cisco Employee

This looks really cool, do you have any info on how to configure the remediation on the Firepower Management Center side of this?

Thanks

Mark

Cisco Employee

OK, so I think that you have to create a file with the pl script and the template like so:

tar cvzf f5.tar.gz f5remR1.pl module.template
Here are the guidelines for importing a remediation module:
https://www.cisco.com/c/en/us/td/docs/security/firesight/540/api/remediation/FireSIGHT-System-Remediation-API-Guide/WritingRemedClients.html#98540
Thanks Ben and Doug