cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1026
Views
0
Helpful
1
Replies

Port Scan auto shun

Hello,

Any one configured ASA5585-X threat detection to auto shun IP Address which are doing port scan..

acl-deny is happening to ports which are not open. But i want to auto-shun the same

I have tried below  steps

threat-detection Basic-Threat

threat-detection rate scanning-threat rate-interval 600 average-rate 10 burst-rate 15

If i configure burst-rate to 0 it will trigger which is not acceptable-solution..

Regards,

-Danish

1 Reply 1

walidazab
Level 1
Level 1

Hi,

What you did is just enabling basic threat detection. You have to also enable scanning threat detection and shunning hosts. You may want to configure a certain time during which shunned hosts will stay blocked. 

I suggest you check the following link it will help you a lot: link: http://www.cisco.com/c/en/us/td/docs/security/asa/asa80/configuration/guide/conf_gd/protect.html#wp1065813

-WA

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card