cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
650
Views
0
Helpful
1
Replies

Blocked IP address disappearing from IPS

s.aliyarukunju
Level 1
Level 1

Dear Experts,

Here in our organization , we have two IPS appliances 4260 and is configured with inline vlan pair mode.Cisco IPS IME is using for monitroing and managing there appliances.

Recently i have added some of the blacklisted public IP addresses ( source IP) under the host block ( Sensor Management > Time-based Actions>Host Blocks)  and after a month , few of the IP address i have added has been disappeared from the blocked list. And whenever i am adding the new IP addresses on this list , i will select the option "No Timeout" to keep these IP address in the list.But still some are disappearing from the box.

Can any one advice what would be the reason for this and how can i make this block list permenant?

Kind Regards,

1 Reply 1

sawgupta
Level 1
Level 1

You can try changing the global-block-timeout:

http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/cliblock.html#wp1031131

Regards,

Sawan Gupta

Thanks & Regards, Sawan Gupta
Review Cisco Networking products for a $25 gift card