cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1340
Views
10
Helpful
5
Replies

Best way to block IPs

CiscoPurpleBelt
Level 6
Level 6

If you need to block IDK malicious IPs and what not, obviously the list could grow very large over time. Also, I know simply blocking a targeted attack may not be effective at preventing DOS/DDOS etc. What would be the best ways to block IPs on lets say an ASA. Would an IPS/IDS be the better solution to implement when it comes to this?

2 Accepted Solutions

Accepted Solutions

The best way to block malicious traffic is to use an IPS.  But if you insist on using the ASA you could use the botnet filter feature.

https://www.cisco.com/c/en/us/td/docs/security/asa/special/botnet/guide/asa-botnet.html

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

venkat_n7
Level 1
Level 1

I would agree with @Marius Gunnerud . but just an HeadsUP! with ASA , if you use that feature on ASA it eats all memory/processing i tried on 5510. 

Please rate comments and support
with regards,
Venkat

View solution in original post

5 Replies 5

The best way to block malicious traffic is to use an IPS.  But if you insist on using the ASA you could use the botnet filter feature.

https://www.cisco.com/c/en/us/td/docs/security/asa/special/botnet/guide/asa-botnet.html

--
Please remember to select a correct answer and rate helpful posts

Looks like I don't have that option on my ASA Firepower
ASDM—the Configuration > Firewall > Botnet Traffic Filter > Botnet Database pane Purge Botnet Database button.

venkat_n7
Level 1
Level 1

I would agree with @Marius Gunnerud . but just an HeadsUP! with ASA , if you use that feature on ASA it eats all memory/processing i tried on 5510. 

Please rate comments and support
with regards,
Venkat

Yes I would nee to test so I am not sure I can use it if that is the case.

CiscoPurpleBelt
Level 6
Level 6
Awesome thanks!
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card