cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
846
Views
0
Helpful
3
Replies

ASA Botnet dynamic-filter drop

Sergey Petrenko
Level 1
Level 1

Hi,

During the configuration dynamic filter I have error:

dynamic-filter drop blacklist

                ^

ERROR: % Invalid input detected at '^' marker.

Show ver result:

---

Cisco Adaptive Security Appliance Software Version 8.2(1)

Device Manager Version 6.2(1)

---

Botnet Traffic Filter        : Enabled  

----

I try apply this configuration:

hostname(config)# dynamic-filter updater-client enable

hostname(config)# dynamic-filter use-database

hostname(config)# class-map dynamic-filter_snoop_class

hostname(config-cmap)# match port udp eq domain

hostname(config-cmap)# policy-map dynamic-filter_snoop_policy

hostname(config-pmap)# class dynamic-filter_snoop_class

hostname(config-pmap-c)# inspect dns preset_dns_map dynamic-filter-snoop

hostname(config-pmap-c)# service-policy dynamic-filter_snoop_policy interface outside

hostname(config)# dynamic-filter enable interface outside

hostname(config)# dynamic-filter drop blacklist interface outside

1 Accepted Solution

Accepted Solutions

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Sergey,

That is not the command you need to run

Please follow the next CSC guide and you will accomplish what you are looking for:

https://supportforums.cisco.com/docs/DOC-8782#8_Define_local_whitelists_andor_blacklists_if_needed

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

3 Replies 3

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Sergey,

That is not the command you need to run

Please follow the next CSC guide and you will accomplish what you are looking for:

https://supportforums.cisco.com/docs/DOC-8782#8_Define_local_whitelists_andor_blacklists_if_needed

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hi,

Thanks, this guide has help me. I see blacklist site in report of botnet.

Can ASA deny site from blacklist automaticaly?

Hello Sergey,

Yeah that is the whole purpose... The ASA will drop or deny this traffic automatically.

Pretty cool right,

Have a great day

Julio Carvajal

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking products for a $25 gift card