Sure, it's easy with IDM. Just go into config -> sensing engine and pick the appropriate engine and signature you want to block on. Set the event action to either ShunHost OR ShunConnection (Host will block all traffic from the source ip Connection will block only the source ip, dest ip, dest port of the attack) You must also set up the sensor and the device it will be applying the shun to. Use the Configuration-> blocking tab for that.