cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1723
Views
5
Helpful
5
Replies

auto blocking IP after alert/ event

paul-d
Level 1
Level 1

Hi,

 

Can firepower / firesight, auto block an IP address if the IP generates an event or an alert. So rather than constantly blocking the attack, i would like FP to actually block the a fending IP for a set period.

 

5 Replies 5

Marvin Rhoads
Hall of Fame
Hall of Fame

Not by itself it cannot.

 

If the offending host is internal and you have something like ISE you can create a correlation policy to have ISE quarantine the host or shutdown the switchport or kick it off the WLAN.

Hi,

 

Thank you, i dont suppose you have any links to any sources? at all  

 

kind regards

Chris.

You're welcome.

 

The Cisco solution is known as Rapid Threat Containment. More information can be found here:

 

https://www.cisco.com/c/en/us/solutions/enterprise-networks/rapid-threat-containment/index.html

While the Rapid Threat Containment working fine for quarantine endpoints in ISE , I am struggling to find a good solution for un-quarantine. Do you know if is is possible to use the FMC REST API to un-quarantine an endpoint based on MAC or IP address?

 

Thanks

/Jorgen

Assuming ISE quarantined the endpoint, it can also unquarantine it and send a message via pxGrid for Firepower to do the same.

 

I'm not sure about using the API directly. Even if the documentation told me I could use the API, I would lab that up first.

Review Cisco Networking for a $25 gift card