cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1782
Views
0
Helpful
4
Replies

Block CodeRed on PIX

vcolla
Level 1
Level 1

Is there any way to block Code Red worm on PIX just as it can be done on Cisco IOS?

4 Replies 4

ciscomoderator
Community Manager
Community Manager

There are a number of Code Red work resources posted at http://www.cisco.com/warp/public/63/codered_index.shtml that you should find useful. I have also learned of another document that will be published shortly that discusses (among other things) the ability of stateful packet filter firewalls (i.e. Cisco PIX Firewall) to help block the adverse affects of the two versions of the worm.

In the meantime, please carefully review the documents at http://www.cisco.com/warp/public/63/codered_index.shtml and http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-033.asp

I will post again to this thread when that document is published.

Thank you for posting your question to the forum.

ciscomoderator
Community Manager
Community Manager

Here is another recently published document regarding the Code Red worm worth reading.

http://www.cisco.com/warp/public/cc/so/cuso/epso/sqfr/scdam_wp.htm

rstaaf
Level 1
Level 1

The PIX can only block by port or IP address so I don't see how you would block it without blocking access to port 80 completely.

My point exactly. I know I can do it on Cisco IOS with class-maps, but how do I do it on PIX?

Review Cisco Networking for a $25 gift card