<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 'shun' command in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-shun-command/m-p/455063#M558322</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as i remember from PIX documentation shun command blocking all traffic originated from IP.&lt;/P&gt;&lt;P&gt;So all the rest of command is ignored.&lt;/P&gt;&lt;P&gt;The PIX shun command always shuns the source address regardless of whether or not the additional connection information is provided.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think in this case better to use access-list statements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 14 May 2005 09:57:24 GMT</pubDate>
    <dc:creator>alexr</dc:creator>
    <dc:date>2005-05-14T09:57:24Z</dc:date>
    <item>
      <title>PIX 'shun' command</title>
      <link>https://community.cisco.com/t5/network-security/pix-shun-command/m-p/455062#M558320</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command is not working as expected.I configured;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# shun 172.16.5.100 144.10.55.1 0 23 tcp&lt;/P&gt;&lt;P&gt;Shun 172.16.5.100 successful&lt;/P&gt;&lt;P&gt;pix(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command blocks all traffic from 172.16.5.100 to "all" destinations. My understanding is that it should only block traffic from 17.16.5.100 to 144.10.55.1 destined for telnet port, 23. But it blocks all traffic originated from 172.16.5.100, including ICMP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;Mohan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-shun-command/m-p/455062#M558320</guid>
      <dc:creator>m.mohanasundaram</dc:creator>
      <dc:date>2020-02-21T08:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 'shun' command</title>
      <link>https://community.cisco.com/t5/network-security/pix-shun-command/m-p/455063#M558322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as i remember from PIX documentation shun command blocking all traffic originated from IP.&lt;/P&gt;&lt;P&gt;So all the rest of command is ignored.&lt;/P&gt;&lt;P&gt;The PIX shun command always shuns the source address regardless of whether or not the additional connection information is provided.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think in this case better to use access-list statements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 May 2005 09:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-shun-command/m-p/455063#M558322</guid>
      <dc:creator>alexr</dc:creator>
      <dc:date>2005-05-14T09:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 'shun' command</title>
      <link>https://community.cisco.com/t5/network-security/pix-shun-command/m-p/455064#M558325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a00801cd841.html#wp1026366" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a00801cd841.html#wp1026366&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 May 2005 16:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-shun-command/m-p/455064#M558325</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-05-14T16:23:30Z</dc:date>
    </item>
  </channel>
</rss>

