cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
672
Views
0
Helpful
3
Replies

Disabling an attacker's IP address after 10 Password Attempts.

conceptzone
Level 1
Level 1

Hi All,

Can I do any configuration on the ASA to dynamically disable an attackers IP address, say for 1 hour  if he/she entered 10 bad password attempts to an email  server ?

Thanks,

Ismail

3 Replies 3

Collin Clark
VIP Alumni
VIP Alumni

That's the role of an IPS sensor. You can plug one into an ASA. It's called the AIP-SSM.

Hi Collin,

So you are you saying that we can't do it through normal access-lists/inspection/etc ? (Without IPS)

Thanks indeed,

Ismail

Correct. If you need to do something dynamic (like shun an IP) IPS is the way to do it.

Review Cisco Networking for a $25 gift card