cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1132
Views
0
Helpful
1
Replies

Prevent Network Scanning

Bethuelle
Level 1
Level 1

Hye,

I am using an AIP-SSM 10. I wish to block block Network Scanning. Is there a way to allow certain Hosts to scan the network without putting them in the Never To Block Addresses List ?

Thanks for your help.

1 Reply 1

rhermes
Level 7
Level 7

You should be careful when blocking the scanning signaturea, these can be easily triggered by simple things like a web browser fetching multiple elements to construct a web page.

If you want to allow you network scanner to remain unblocked you should look at Event Action Overrides and Event Action Filters:

http://www.cisco.com/en/US/partner/docs/security/ips/7.1/configuration/guide/cli/cli_event_action_rules.html

- Bob

Review Cisco Networking for a $25 gift card