02-25-2016 08:46 PM - edited 03-12-2019 05:54 AM
Hello,
Does FireSIGHT is allow to auto blacklist the IP if hit the rule like SHUN? rather than manually blacklist IP.
Thanks!
02-25-2016 08:56 PM
Hi,
It uses the Global blacklist feature by Security intelligence , if you want to add any other IP's in that you have to add that manually.
Check this : http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/AC-Secint-Blacklisting.html
Regards,
Aastha Bhardwaj
Rate if that helps!!!
02-25-2016 09:40 PM
Hello,
Intelligence Feed is depending on DB. However, the IPs may not in the list so it will not suitable for my case.
Seems only allow manual blacklist? As it cannot 24x7 to monitor the log.
Thanks!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: