05-14-2023 07:24 PM
Hello,
If we only have cisco cat4500 and 9500 as the core switch and C2960x as distribution and access switch, what can we do to prevent ransomware attacked the internal resource?
05-15-2023 12:14 AM
- Use business level (oriented) firewalls on the perimeter , such a Palo Alto or other. It has sufficient strength to block that,
M.
05-15-2023 01:50 AM
Not a bl**dy thing.
05-15-2023 06:59 AM - edited 05-15-2023 06:59 AM
If you already have ransomware in the network it's probably too late to do anything.
If it hasn't spread everywhere yet then shutdown switch ports to isolate affected parts completely until they're certified "clean".
If you're looking to implement something as prevention then that's not something you can do just on switches. It's a total security solution - every single part of the network and IT needs to be included in the solution.
Good summary (and some product links) here: https://www.cisco.com/c/en_uk/solutions/security/ransomware-defense/index.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide