<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: auto blocking IP after alert/ event in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3316722#M926149</link>
    <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Cisco solution is known as Rapid Threat Containment. More information can be found here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/solutions/enterprise-networks/rapid-threat-containment/index.html" target="_blank"&gt;https://www.cisco.com/c/en/us/solutions/enterprise-networks/rapid-threat-containment/index.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jan 2018 13:21:35 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-01-23T13:21:35Z</dc:date>
    <item>
      <title>auto blocking IP after alert/ event</title>
      <link>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3310283#M926146</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can firepower / firesight, auto block an IP address if the IP generates an event or an alert. So rather than constantly blocking the attack, i would like FP to actually block the a fending IP for a set period.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:07:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3310283#M926146</guid>
      <dc:creator>paul-d</dc:creator>
      <dc:date>2020-02-21T15:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: auto blocking IP after alert/ event</title>
      <link>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3312952#M926147</link>
      <description>&lt;P&gt;Not by itself it cannot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the offending host is internal and you have something like ISE you can create a correlation policy to have ISE quarantine the host or shutdown the switchport or kick it off the WLAN.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 15:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3312952#M926147</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-01-17T15:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: auto blocking IP after alert/ event</title>
      <link>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3316574#M926148</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you, i dont suppose you have any links to any sources? at all&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;kind regards&lt;/P&gt;
&lt;P&gt;Chris.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 09:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3316574#M926148</guid>
      <dc:creator>paul-d</dc:creator>
      <dc:date>2018-01-23T09:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: auto blocking IP after alert/ event</title>
      <link>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3316722#M926149</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Cisco solution is known as Rapid Threat Containment. More information can be found here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/solutions/enterprise-networks/rapid-threat-containment/index.html" target="_blank"&gt;https://www.cisco.com/c/en/us/solutions/enterprise-networks/rapid-threat-containment/index.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 13:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3316722#M926149</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-01-23T13:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: auto blocking IP after alert/ event</title>
      <link>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3321620#M926150</link>
      <description>&lt;P&gt;While the&amp;nbsp;&lt;SPAN&gt;Rapid Threat Containment working fine for quarantine endpoints in ISE , I am struggling&amp;nbsp;to find a good solution for un-&lt;/SPAN&gt;quarantine. Do you know if is is possible to use the FMC REST API to un-quarantine an endpoint based on MAC or IP address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Jorgen&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 13:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3321620#M926150</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2018-01-30T13:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: auto blocking IP after alert/ event</title>
      <link>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3321678#M926151</link>
      <description>&lt;P&gt;Assuming ISE quarantined the endpoint, it can also unquarantine it and send a message via pxGrid for Firepower to do the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure about using the API directly. Even if the documentation told me I could use the API, I would lab that up first.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 14:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-blocking-ip-after-alert-event/m-p/3321678#M926151</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-01-30T14:46:35Z</dc:date>
    </item>
  </channel>
</rss>

