<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS version 6.2 blocking help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119262#M78580</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohammad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are three type of blocks on the Cisco IPS, connection block enabled referred to the blocks that match no both source/dest etc. and not just the source. From the user guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"There are three types of blocks: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Host block-Blocks all traffic from a given IP address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Connection block-Blocks traffic from a given source IP address to a given destination IP address and destination port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Multiple connection blocks from the same source IP address to either a different destination IP address or destination port automatically switch the block from a connection block to a host block. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note Connection blocks are not supported on firewalls. Firewalls only support host blocks with additional connection information. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Network block-Blocks all traffic from a given network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can initiate host and connection blocks manually or automatically when a signature is triggered. You can only initiate network blocks manually. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Caution Do not confuse blocking with the sensor's ability to drop packets. The sensor can drop packets when the following actions are configured for a sensor in inline mode: deny packet inline, deny connection inline, and deny attacker inline. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Oct 2008 12:39:50 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-10-21T12:39:50Z</dc:date>
    <item>
      <title>IPS version 6.2 blocking help</title>
      <link>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119261#M78579</link>
      <description>&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please find the attached file.&lt;/P&gt;&lt;P&gt;i have ips 4240 and it is working properly.&lt;/P&gt;&lt;P&gt;i tuned some signatures to block the connections for any pc that has abnormal traffic or try to use P2P application but i want to know something in the attached file , what is the difference between &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;connection block enabled ----&amp;gt; true&lt;/P&gt;&lt;P&gt;connection block enabled ----&amp;gt; false&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words , what is the meaning of ture and false in the attached file???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;waiting for your replies .&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Mohamed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119261#M78579</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2019-03-10T11:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPS version 6.2 blocking help</title>
      <link>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119262#M78580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohammad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are three type of blocks on the Cisco IPS, connection block enabled referred to the blocks that match no both source/dest etc. and not just the source. From the user guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"There are three types of blocks: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Host block-Blocks all traffic from a given IP address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Connection block-Blocks traffic from a given source IP address to a given destination IP address and destination port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Multiple connection blocks from the same source IP address to either a different destination IP address or destination port automatically switch the block from a connection block to a host block. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note Connection blocks are not supported on firewalls. Firewalls only support host blocks with additional connection information. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Network block-Blocks all traffic from a given network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can initiate host and connection blocks manually or automatically when a signature is triggered. You can only initiate network blocks manually. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Caution Do not confuse blocking with the sensor's ability to drop packets. The sensor can drop packets when the following actions are configured for a sensor in inline mode: deny packet inline, deny connection inline, and deny attacker inline. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2008 12:39:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119262#M78580</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-21T12:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPS version 6.2 blocking help</title>
      <link>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119263#M78582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply and your support. What  i need to know what is the meaning of True and False in the Connection Block Enabled column in the attached file????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2008 16:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119263#M78582</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2008-10-21T16:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPS version 6.2 blocking help</title>
      <link>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119264#M78584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Mohammad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When that field is set to true, then it means a "Connection block" is being done instead of a "Host block" (based on source IP only). When it is false it implies a "Host Block".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2008 06:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-version-6-2-blocking-help/m-p/1119264#M78584</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-22T06:34:30Z</dc:date>
    </item>
  </channel>
</rss>

