How To Set Up Manual Blocking And How To Unblock - Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual

Intrusion detection system appliance and module
Table of Contents

Advertisement

Sensor Configuration Tasks

How to Set up Manual Blocking and How to Unblock

Note
Caution
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
10-76
ShunInterface
InterfaceName = ethernet1
InterfaceDirection = in
State
ShunEnable = true
NetDevice
IP = 10.89.150.160
AclSupport = uses Named ACLs
State = Active
ShunnedAddr
Host
IP = 10.16.0.0
ShunMinutes = 15
MinutesRemaining = 15
Host
IP = 192.168.16.0
ShunMinutes = 10
MinutesRemaining = 10
The last two
entries indicate which hosts are being blocked and how long the
Host
blocks are.
If you have blocking configured, you can manually block a host. You can also
view a list of hosts that are being blocked.
Manual blocks in the CLI are actually changes to the configuration, so they are
permanent. You cannot do a timed manual block. You cannot use the IDSM or IDS
MC to delete blocks created by the CLI. Manual blocks have to be removed in the
CLI.
We recommend that you use manual blocking on a very limited basis, if at all.
Chapter 10
Configuring the Sensor Using the CLI
78-15597-02

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?

Questions and answers

Table of Contents