<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDSM2 version 4.1 blocking attacks in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm2-version-4-1-blocking-attacks/m-p/500416#M91452</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have set up a IDSM2 version 4.1 on a Cisco Catalyst 6500 switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have configured it using SPAN on specific vlans and if we run a port sweep, we can see the alarms on the IDS viewer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible to stop any attack by dropping packets/ flows or blocking dynamically the source ip address of the attack ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nikos&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:41:12 GMT</pubDate>
    <dc:creator>nmourtzinos</dc:creator>
    <dc:date>2019-03-10T09:41:12Z</dc:date>
    <item>
      <title>IDSM2 version 4.1 blocking attacks</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-version-4-1-blocking-attacks/m-p/500416#M91452</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have set up a IDSM2 version 4.1 on a Cisco Catalyst 6500 switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have configured it using SPAN on specific vlans and if we run a port sweep, we can see the alarms on the IDS viewer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible to stop any attack by dropping packets/ flows or blocking dynamically the source ip address of the attack ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nikos&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-version-4-1-blocking-attacks/m-p/500416#M91452</guid>
      <dc:creator>nmourtzinos</dc:creator>
      <dc:date>2019-03-10T09:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 version 4.1 blocking attacks</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-version-4-1-blocking-attacks/m-p/500417#M91454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the system detects unauthorized activity, appliances can terminate the specific connection, permanently block the attacking host, log the incident, and send an alert to the IDS manager. Other legitimate connections continue to operate independently without interruption. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_installation_and_configuration_guide_chapter09186a0080358053.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_installation_and_configuration_guide_chapter09186a0080358053.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2005 15:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-version-4-1-blocking-attacks/m-p/500417#M91454</guid>
      <dc:creator />
      <dc:date>2005-10-18T15:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 version 4.1 blocking attacks</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-version-4-1-blocking-attacks/m-p/500418#M91456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IDSM-2 as the IDS sensor is allowed to initiate blocking to other devices either through IDM or CiscoWorks VMS (IDS MC), for automatic blocking you just assign block as eventAction for the desired signature and the IDSM-2 will push an VACL to the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_example09186a00801e8181.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_example09186a00801e8181.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2005 18:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-version-4-1-blocking-attacks/m-p/500418#M91456</guid>
      <dc:creator>abdel_n</dc:creator>
      <dc:date>2005-10-18T18:16:13Z</dc:date>
    </item>
  </channel>
</rss>

