05-09-2012 07:56 PM - edited 03-11-2019 04:04 PM
Hi guys,
I've had a strange question from my boss about security on a Cisco ASA 5520. I've just started to study for the CCNA security, so I would not give a wrong answer caused by my inexperience.
The question is: Is it possible to automatically shutdown the OUTSIDE interface on a Cisco ASA 5520 in case of intrusion?.
In my opinion if there is an attempt of intrusion, just the device woud stop it. If it cannot detect it, how can the device recognize the event and so shutdown the interface?. Am I correct?
Thanks,
Dario
Solved! Go to Solution.
05-09-2012 09:39 PM
Dario,
Well, shut down the interface? Nope, however, there are many ways on which in case of an intrusion, another device can detect the traffic and shun (block the host). That can be accomplish using an IPS device in conjuction with the host block capability.
If by intrusion you mean, insertion of code or something that goes more like on a Payload perspective, there are some features that can be enable on the ASA itself to block the request (reset the connection). With an IPS, you have a lot of signatures that are meant to detect an intrusion on the network and a signal to block the host/connection is sent to a blocking device (in this case the ASA).
There is just so many things, but nothing like shut down the interface.
Mike
05-09-2012 09:39 PM
Dario,
Well, shut down the interface? Nope, however, there are many ways on which in case of an intrusion, another device can detect the traffic and shun (block the host). That can be accomplish using an IPS device in conjuction with the host block capability.
If by intrusion you mean, insertion of code or something that goes more like on a Payload perspective, there are some features that can be enable on the ASA itself to block the request (reset the connection). With an IPS, you have a lot of signatures that are meant to detect an intrusion on the network and a signal to block the host/connection is sent to a blocking device (in this case the ASA).
There is just so many things, but nothing like shut down the interface.
Mike
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide