11-04-2011 07:48 AM - edited 03-10-2019 05:32 AM
Hi All!
I was told by an engineer that the IPS sensor can be configured to configure a timed ACL on a router based on IPS alerts it receives (to block a specific IP address for example). Is this true? I did a search but as you can imagine all the results that are returned are for configuring IPS on the router (IOS IPS).
Can anyone point me to a document or somewhere I can get more info?
Thanks much!
Regards,
Xavier
Solved! Go to Solution.
11-04-2011 08:43 AM
Xavier -
You were told correctly, Cisco IPS Sensors can create a temporary ACL in Cisco IOS routers and Cisco PIX/ASA Firewalls. The feature you are looking for is called "Shunning" or "Blocking".
You need to enable shunning for the signatures you wish to shun, and configure the IPS sensor with the necessary credentials, interface and direction on the router you want the ACL to appear.
Here is a CLI configuration example:
And here is an IME configuration example:
- Bob
11-04-2011 08:43 AM
Xavier -
You were told correctly, Cisco IPS Sensors can create a temporary ACL in Cisco IOS routers and Cisco PIX/ASA Firewalls. The feature you are looking for is called "Shunning" or "Blocking".
You need to enable shunning for the signatures you wish to shun, and configure the IPS sensor with the necessary credentials, interface and direction on the router you want the ACL to appear.
Here is a CLI configuration example:
And here is an IME configuration example:
- Bob
11-04-2011 02:28 PM
Exactly what I needed! Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide