I am trying to implement a solution to block all traffic through an ASA device in case of an intrusion, and the block would be lifted manually later. Any idea how this can be achieved?
12-11-2017 12:01 PM - edited 02-21-2020 06:56 AM
I am trying to implement a solution to block all traffic through an ASA device in case of an intrusion, and the block would be lifted manually later. Any idea how this can be achieved?
12-11-2017 01:44 PM
12-12-2017 07:43 AM
I'm not using ISE, just an ASA 5508-X with Firepower. The problem I have with the IOS Null route remediation is that it uses telnet.
I have looked at the remediation subsystem, and one of the methods I thought of is creating an access control policy which blocks Ingress and Egress traffic for an IP range in the Firepower management center and deploying it using a custom remediation. But, is it possible to deploy an access control policy from the FMC command line?
12-12-2017 01:57 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide