cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1561
Views
3
Helpful
2
Replies

IDS Shunning on a PIX

andy
Level 1
Level 1

I have a IDS 4215 that I configured a PIX blocking device on. It appears to be set up correctly, but I am not sure how I can confirm the setup. Are there any methods to confirm its configuration? Thanks in advance.

2 Replies 2

jlively
Cisco Employee
Cisco Employee

There are several ways. Log into the cli on the sensor and do a show stat net. You should see the pix listed with a status of active. Next log into the pix. Do a show shun and you should see all current shuns. (NOTE: The active shuns are also shown in the show stat net output for comparison.) In order for the sensor to create shuns on the pix, signatures have to be configured to either shun/block host or shun/block connection (but not both). You can use IDM to create a manual shun if you are not generating automatic alarms.

OK, thanks. the show stat net command echoed back some good info. The PIX shows no active shuns, but I assume that is because there is nothing happening at the moment. Thanks for your post.

Review Cisco Networking for a $25 gift card