<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inside servers shunned in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588161#M564606</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;with the command "sh threat-detection shun" you can tell if they are being shunned. A syslog message would be generated in that case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that happens again should be able to check the result of the command and the logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Mar 2011 16:23:01 GMT</pubDate>
    <dc:creator>PAUL GILBERT ARIAS</dc:creator>
    <dc:date>2011-03-02T16:23:01Z</dc:date>
    <item>
      <title>inside servers shunned</title>
      <link>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588160#M564602</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A client suffered an outage with their isp today with a ASA5505 running 8.4(1).The connection bounced for about an hour or so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would appear a side effect of the outage is the ASA shunned two inside servers. The configuration was set to detect scanning threats and shun them, but it did not specify to exclude this network which is not directly connected but is on the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm curious if the outage actually caused this but don't understand any conditions in which these servers would be scanning the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone shed some light on this? Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:59:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588160#M564602</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2019-03-11T19:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: inside servers shunned</title>
      <link>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588161#M564606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;with the command "sh threat-detection shun" you can tell if they are being shunned. A syslog message would be generated in that case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that happens again should be able to check the result of the command and the logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 16:23:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588161#M564606</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-02T16:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: inside servers shunned</title>
      <link>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588162#M564610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did a sh shun and it listed them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do save the logs on this ASA so it will be a matter of going through them, but I'm still curious what others have to say.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 16:30:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588162#M564610</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-03-02T16:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: inside servers shunned</title>
      <link>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588163#M564613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;opened a tac case earlier in the day. I'll let you know if they come up with anything worth posting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 22:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-servers-shunned/m-p/1588163#M564613</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-03-02T22:43:01Z</dc:date>
    </item>
  </channel>
</rss>

