Submit a ticketCall us

Solarwinds & Cisco Live! Barcelona
Join us from the 29th of January to the 2nd of February at Cisco Live 2018 in Barcelona, where we will continue to show how monitoring the network with SolarWinds will keep you ahead of the game. At our booth (WEP 1A), we will demonstrate how SolarWinds network solutions can help. As a bonus, we are also hosting a pre-event webinar - Blame the Network, Hybrid IT Edition with our SolarWinds Head Geek™, Patrick Hubbard on January 24th - GMT (UTC+0): 10:00 a.m. to 11:00 a.m. There's still time to RSVP.

Home > Success Center > Log & Event Manager (LEM) > Block IP Active Response

Block IP Active Response

Created by Interspire Import, last modified by Tim Rush on Apr 27, 2017

Views: 1,116 Votes: 0 Revisions: 12

Overview

Use the Block IP active response to block an IP address at your firewall using your LEM appliance. This action is useful for blocking port scanners and can be automated in a LEM rule or executed manually from the Respond menu in the LEM Console.

If this is not working, see Additional information below.

Requirements

You can use the Block IP active response with the following firewalls/modules.

  • Cisco PIX
  • Cisco ASA
  • Cisco Firewall Services Module
  • FortiGate
  • Juniper NetScreen
  • Check Point OPSEC
  • SonicWALL
  • WatchGuard Firebox (including Vclass)

Configure the Active Response connector for one of the firewalls listed above on your LEM appliance.

To configure the Active Response connector for your firewall:

  1. Open your LEM console and log in as an administrator.
  2. Click the Manage tab, and then select Appliances.
  3. Click the gear icon to the left of your LEM Manager, and then select Connectors.
  4. Select Firewalls from the Category list, and enter active response in the search box at the top of the Refine Results pane.
  5. Click the gear icon next to the connector for your firewall, and then select New.
  6. Complete the Connector Configuration form according to your firewall's specifications.
    Note: Generally, all you will have to enter is your firewall address and credentials. Some connectors, however, require more information. 
  7. Click Save.
  8. Click the gear icon next to the new connector (denoted by an icon in the Status column), and then select Start.
  9. Click Close to exit the Connector Configuration window.

Additional Information

The Block IP active response creates a rule on your firewall to block the IP addresses you specify. To allow an IP address through your firewall, delete or modify the rule on your firewall as appropriate.

  1. Overview
  2. Requirements
  3. Additional Information


Firewall Vendors have changed  their default level of ciphers allowed to make firewall changes (block IP).
Historically 3DES ciphers were allowed to shun (block) IP addresses, but in March 2017, the minimum default was raised to AES, which broke our active response connector (tool) for all LEM versions up to & including 6.3.1-HF4.
LEM 6.4.0 has the new ciphers.
Any previous version needs to be upgraded to at least 6.3.1 and hotfix-4, before installing buddy-drop-11.

Here is the download:
     http://downloads.solarwinds.com/sola...CUST-29013.zip

Contact Solarwinds Support to have the buddy-drop installed.
 

Last modified

Tags

Classifications

Public