cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
369
Views
2
Helpful
4
Replies

How to block an IP address on FTD based on Priority and Classification

Sopera
Level 1
Level 1

Dear Community,

I am searching for a solution to automatically add the source IP of an attacker to the global block list when they perform a Priority Impact 1/2 attack.

Regards

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

You can manually add the IP in to Black list or if the IP blocked security intellegence to get the feeds.

you need to find a way to manipulate using API based on the attack vector and add in to block list, that is what i am thinking my views

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

in addition what i have said before use below guide to  see if that work for you.

Protect Servers from a SYN Flood DoS Attack (TCP Intercept)

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/threat_defense_service_policies.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

if this IP run any DDoS then try 
use flexconfig and thread-detection shun
MHM

Can you provide me the flexconfig commands to do the same ,

Flex config is very hard to create

Review Cisco Networking for a $25 gift card