<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Shunned in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679205#M558397</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Login to the device, and issue the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tls generate-key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_qanda_item09186a008025c533.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_qanda_item09186a008025c533.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this would genrate new key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 16 Jul 2011 04:22:24 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2011-07-16T04:22:24Z</dc:date>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679183#M558360</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a server having ip address 172.21.X.X, and it is always getting shunned. I have to manually clear the shuna everytime. Why the server is getting blocked at shun, i am unable to understand ? I can bypass the server adress at shun, but that's not solution. The server contains linux OS. Can anyone please help on this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679183#M558360</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2019-03-11T20:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679184#M558365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best way to find out would be to enable debug level logging and wait for the server to be shunned again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs should give more insight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 09:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679184#M558365</guid>
      <dc:creator>padatta</dc:creator>
      <dc:date>2011-04-07T09:51:46Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679185#M558367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the debug command for shun ? I have searched a lot over internet, but counldn't find anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jul 2011 15:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679185#M558367</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-11T15:57:25Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679186#M558371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u explain what is the purpose for it, what information are you trying to see??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jul 2011 16:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679186#M558371</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-11T16:37:40Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679187#M558376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As suggested by Mr. Padatta, i am trying to do debug level logging for the shunned server. It's creating a lot of problem when the server are getting shunned and i have to remove it manually. Is there is any other way to solve this issue ? Please help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 03:23:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679187#M558376</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-12T03:23:39Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679188#M558379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no debug command for shun, wat he suggested wasd takong logs friom the ASA at debug level:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To enable it you need the command:&lt;/P&gt;&lt;P&gt;logging buffered 7&lt;/P&gt;&lt;P&gt;logging monitor 7&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;logging trap 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;level 7 is for debugging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is a doc:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/customer/docs/security/asa/asa82/system/message/logsevp.html"&gt;http://www.cisco.com/en/US/customer/docs/security/asa/asa82/system/message/logsevp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805a2e04.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805a2e04.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 03:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679188#M558379</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-12T03:37:38Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679189#M558381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have enabled debugging on ASA. It's only showing the below mentioned message :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Shunned packet: 172.21.x.x ==&amp;gt; 10.40.x.x on interface DMZ&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 05:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679189#M558381</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-12T05:30:11Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679190#M558382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to see what all Ip addresses are getting shunned on the firewall, use the command "show shun", now the IP addresses that should not be shunned, add a "no" in front of them and save the changes, those ip's would be removed from the shun list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/customer/docs/security/asa/asa82/command/reference/s8.html#wp1525925"&gt;http://www.cisco.com/en/US/customer/docs/security/asa/asa82/command/reference/s8.html#wp1525925&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 06:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679190#M558382</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-12T06:00:00Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679191#M558383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried with "no shun ip address" command with saving the changes, but after sometime it's again getting shunned.&lt;/P&gt;&lt;P&gt;Is there any other way ? Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 05:54:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679191#M558383</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-13T05:54:30Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679192#M558384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a bit confused about your issue here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you not able to access a server and the reason taht you see in the logs is because it has been shunned ?? You have tried removing the shun command but after sometime does comeback on the firewall????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am asking you this because the access to the server could be blocked due to someother reason as well, do you always see the ip of the server in the shunned list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;provide me the following outputs:&lt;/P&gt;&lt;P&gt;ip of the server&lt;/P&gt;&lt;P&gt;show shun&lt;/P&gt;&lt;P&gt;the logs that you get when you access the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 07:08:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679192#M558384</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-13T07:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679193#M558385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are able to access and ping the server, before shun. As soon as it get shunned, we are neither able to ping nor access to the server. After removing with no shun command, then we are able to access and ping the server. After sometime the server ip automatically get shun. Yes, the server ip is always get shunned. The server is our dns server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP of the server : 172.21.10.13&lt;/P&gt;&lt;P&gt;Show shun : shun (DMZ) 172.21.10.13 0.0.0.0 0 0 0&lt;/P&gt;&lt;P&gt;The logs that you get when you access the server: Built outbound TCP connection 197491880 for DMZ:172.21.10.13/22 (172.15.22/22) to INSIDE:172.21.15.12 (172.21.15.12/1122)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 08:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679193#M558385</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-13T08:55:06Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679194#M558386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me to solve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jul 2011 15:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679194#M558386</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-14T15:40:40Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679195#M558387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Automatic shunning can happen on ASAs because of 2 reasons:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You have scanning threat-detection enabled iwth shunning on the ASA.&lt;/P&gt;&lt;P&gt;2) There is an IPS device configured on your network for blocking which adds this shun on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Please post the output of &lt;STRONG&gt;show run all threat-detection&lt;/STRONG&gt; from the ASA.&lt;/P&gt;&lt;P&gt;2) Do you have a Cisco IPS in your network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jul 2011 16:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679195#M558387</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2011-07-14T16:09:10Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679196#M558388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh run all threat-detection (output)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;threat-detection rate dos-drop rate-interval 600 average-rate 100 burst-rate 400&lt;/P&gt;&lt;P&gt;threat-detection rate dos-drop rate-interval 3600 average-rate 80 burst-rate 320&lt;/P&gt;&lt;P&gt;threat-detection rate bad-packet-drop rate-interval 600 average-rate 100 burst-rate 400&lt;/P&gt;&lt;P&gt;threat-detection rate bad-packet-drop rate-interval 3600 average-rate 80 burst-rate 320&lt;/P&gt;&lt;P&gt;threat-detection rate acl-drop rate-interval 600 average-rate 400 burst-rate 800&lt;/P&gt;&lt;P&gt;threat-detection rate acl-drop rate-interval 3600 average-rate 320 burst-rate 640&lt;/P&gt;&lt;P&gt;threat-detection rate conn-limit-drop rate-interval 600 average-rate 100 burst-rate 400&lt;/P&gt;&lt;P&gt;threat-detection rate conn-limit-drop rate-interval 3600 average-rate 80 burst-rate 320&lt;/P&gt;&lt;P&gt;threat-detection rate icmp-drop rate-interval 600 average-rate 100 burst-rate 400&lt;/P&gt;&lt;P&gt;threat-detection rate icmp-drop rate-interval 3600 average-rate 80 burst-rate 320&lt;/P&gt;&lt;P&gt;threat-detection rate scanning-threat rate-interval 600 average-rate 5 burst-rate 10&lt;/P&gt;&lt;P&gt;threat-detection rate scanning-threat rate-interval 3600 average-rate 4 burst-rate 8&lt;/P&gt;&lt;P&gt;threat-detection rate syn-attack rate-interval 600 average-rate 100 burst-rate 200&lt;/P&gt;&lt;P&gt;threat-detection rate syn-attack rate-interval 3600 average-rate 80 burst-rate 160&lt;/P&gt;&lt;P&gt;threat-detection rate fw-drop rate-interval 600 average-rate 400 burst-rate 1600&lt;/P&gt;&lt;P&gt;threat-detection rate fw-drop rate-interval 3600 average-rate 320 burst-rate 1280&lt;/P&gt;&lt;P&gt;threat-detection rate inspect-drop rate-interval 600 average-rate 400 burst-rate 1600&lt;/P&gt;&lt;P&gt;threat-detection rate inspect-drop rate-interval 3600 average-rate 320 burst-rate 1280&lt;/P&gt;&lt;P&gt;threat-detection rate interface-drop rate-interval 600 average-rate 2000 burst-rate 8000&lt;/P&gt;&lt;P&gt;threat-detection rate interface-drop rate-interval 3600 average-rate 1600 burst-rate 6400&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection scanning-threat shun duration 3600&lt;/P&gt;&lt;P&gt;threat-detection statistics host&lt;/P&gt;&lt;P&gt;threat-detection statistics port&lt;/P&gt;&lt;P&gt;threat-detection statistics protocol&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Yes, we have Cisco IPS in our network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 07:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679196#M558388</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-15T07:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679197#M558389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would need to verify it on the IPS as well as threat-detection as well:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For threat-detection you can use the "except" keyword to exclude your server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection scanning-threat shun except ip-address 172.21.10.13 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To check on IP, login to the IDM, and on the top go to monitoring------&amp;gt; Active hosts Block--------&amp;gt; There you can see if this server is being blocked by the IPS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is blocked by IPS, go to Configuration ----------&amp;gt; Blocking Properties -----------&amp;gt; Never block IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screenshot are attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 07:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679197#M558389</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-15T07:33:45Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679198#M558390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the server is getting blocked, it is showing at shun on ASA but it's not showing at IPS under Active host block. As suggested by you if i configure threat-detection scanning-threat shun except ip-address 172.21.10.13 255.255.255.255 command, then the server is not getting shunned or blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can i verify with server ip address at IPS whether any signature is getting tuned for this server ? Is threat-detection scanning-threat shun except ip-address 172.21.10.13 255.255.255.255 is the best way to configure ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS is configured in inline mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 08:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679198#M558390</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-15T08:28:41Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679199#M558391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can check it, but in IME, go to IME ---------&amp;gt; Event Monitoring and then filter tab, filter by attacker ip first, if it doesnt help, filter by victim ip and search, this hsould work for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 09:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679199#M558391</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-15T09:33:46Z</dc:date>
    </item>
    <item>
      <title>Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679200#M558392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Event Monitoring option is not showing. Is there any option to enable it. I have searched at internet but couldn't find anything. Please find the screenshot of what options are available at IPS.&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/3/9/52933-IPS%201.JPG" class="jive-image" /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/3/9/52934-IPS%202.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 11:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679200#M558392</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-15T11:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679201#M558393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was talking about the Cisco IME, please find the screenshot attached&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 11:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679201#M558393</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-15T11:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Shunned</title>
      <link>https://community.cisco.com/t5/network-security/shunned/m-p/1679202#M558394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have installed Cisco IME 7.1.1. While trying to add IPS device, it's giving the below mentioned error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IOException when try to get certificate: java.security.cert.Certificate expired exception : Not After Mon Jun 13 05:51:27 GMT +5:30 2011&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think certificate has got expired, but which certificate has got expired i am unable to understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i tried to add IDSM device, the following error has occured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IOException when try to get certificate: Read timed out.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 18:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shunned/m-p/1679202#M558394</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-15T18:02:54Z</dc:date>
    </item>
  </channel>
</rss>

