Security Compliance

Configure the Block IP active response in SEM

Use the Block IP active response to block an IP address at your firewall using your SEM appliance. This action is useful for blocking port scanners and can be automated in a SEM rule or executed manually from the Respond menu in the SEM Console.

First published date

10/19/2018 10:40 PM

Last published date

11/18/2024 11:56 PM

Overview

Use the Block IP active response to block an IP address at your firewall using your Security Event Manager (formerly Log & Event Manager) appliance. This action is useful for blocking port scanners and can be automated in a SEM rule or executed manually from the Respond menu by navigating to Build > nDepth in the SEM Flash console.
 

If this is not working, see Additional Information below.

Product section

Security Event Manager

Resolution

Requirements 

You can use the Block IP active response with the following firewalls/modules.

  • Cisco PIX
  • Cisco ASA
  • Cisco Firewall Services Module
  • FortiGate
  • Juniper NetScreen
  • Check Point OPSEC
  • SonicWALL
  • WatchGuard Firebox (including Vclass)


Configure the Active Response connector for one of the firewalls listed above on your LEM appliance.

 

Configure the Active Response connector for your firewall:

HTML5 console (versions 6.6 and newer)

  1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
  2. In the search box, enter active response.
  3. Select your firewall active response connector, and then click Add Connector.
  4. Complete the connector configuration form according to your firewalls specifications, and then click Add.
  5. Under Configured connectors, select the connector, and then click Start.

Configure the Rule (versions 6.7 and newer):

  1. In the SEM Events Console, click the Rules tab.
  2. On the Rules toolbar, click Create new rule.
  3. Drag one or more values into the rule definition builder. The drag panel on the left contains searchable filter values that you can drag into the rule definition builder. Expand a rule values group to select a value, or locate your value by entering a term in the search field.  

    Note: When you drag a value into the filter builder, the correct drop location is illuminated with a blue line. Learn more here.

  4. Click Next.
  5. Under details and actions, add a descriptive rule name.
  6. To add the Active Response tag to your rule, click Add tag, and then select it from the Activity Types list.
  7. Click a toggle button to enable the rule after saving, or to enable in test mode.
  8. Click Add new action, select Block IP, and then click Next.
  9. Enter the IP address to be blocked, click Add, and then click Create.

SEM Flash console

  1. Open your LEM console and log in as an administrator.
  2. On the LEM toolbar, navigate to Manage > Appliances.
  3. To the left of your LEM Manager, click the gear icon, and then select Connectors.
  4. Select Firewalls from the Category list, and enter active response in the search box at the top of the Refine Results pane.
  5. Click the gear icon next to the connector for your firewall, and then select New.
  6. Complete the Connector Configuration form according to your firewall's specifications.

    Note: Generally, all you will have to enter is your firewall address and credentials. Some connectors, however, require more information. 

  7. Click Save.
  8. Click the gear icon next to the new connector (denoted by an icon in the Status column), and then select Start.
  9. Click Close to exit the Connector Configuration window.

 

    Additional Information

    The Block IP active response creates a rule on your firewall to block the IP addresses you specify. To allow an IP address through your firewall, delete or modify the rule on your firewall as appropriate.
    Firewall Vendors have changed their default level of ciphers allowed to make firewall changes (block IP).
    Historically 3DES ciphers were allowed to shun (block) IP addresses, but in March 2017, the minimum default was raised to AES, which broke our active response connector for all SEM versions up to & including 6.3.1-HF4.
    SEM 6.4 and newer has the new ciphers.

    If your configured Alert triggers correctly but won't restart the Windows services
    From Edit Start Windows Service for  Agent: select  " ServiceSTop.DetectionIP"
    For Service name: Select   "ServiceSTop.ServiceName"