06-08-2017 02:06 AM - edited 03-12-2019 06:25 AM
Hi,
We have FirePower managed by FireSight, and i was wondering, can you get FireSight to blacklist an IP when it say identifies the sender as emailing malware?
Or set an IPS policy to blacklist the source IP address when a malware event is triggered, for a period of say 24 hours?
Thank You
Chris
Solved! Go to Solution.
06-08-2017 08:25 PM
Yes - you use Correlation Policy with rules and remediations for this.
The logic of doing it is a bit complex (in my opinion) but you can watch the excellent labminutes video on this topic to learn how.
http://www.labminutes.com/sec0177_asa_firepower_event_correlation_remediation_1
06-08-2017 08:25 PM
Yes - you use Correlation Policy with rules and remediations for this.
The logic of doing it is a bit complex (in my opinion) but you can watch the excellent labminutes video on this topic to learn how.
http://www.labminutes.com/sec0177_asa_firepower_event_correlation_remediation_1
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide