cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7401
Views
10
Helpful
5
Replies

How do you exclude an IP address from Threat Detection in ASA

uhl_frederick
Level 1
Level 1

Hello,

I run ping scans on certain subnets that may or may not be conneceted to ports on my ASA. I need to exclude my workstation IP address from being flagged as a threat. Anyone know how to do this?

Thanks

Gene

1 Accepted Solution

Accepted Solutions

JORGE RODRIGUEZ
Level 10
Level 10

Gene,

you may try:

e.i, your host IP conducting scans : 20.20.20.20

threat-detection scanning-threat shun except ip-address 20.20.20.20 255.255.255.255

Go over this link

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/t.html#wp1499634

Jorge Rodriguez

View solution in original post

5 Replies 5

JORGE RODRIGUEZ
Level 10
Level 10

Gene,

you may try:

e.i, your host IP conducting scans : 20.20.20.20

threat-detection scanning-threat shun except ip-address 20.20.20.20 255.255.255.255

Go over this link

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/t.html#wp1499634

Jorge Rodriguez

Hello,

will the exclusion work even if I don't have enabled the shun option yet?

Is this Firepower related?
Can I quickly "except a host from Firepower scan" with this command?

It's ASA Threat detection feature

How to disable/deleted it?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card