Submit a ticketCall us
Home > Success Center > Log & Event Manager (LEM) > How does Cisco Block IP active response work

How does Cisco Block IP active response work

Table of contents

Updated March 10, 2017

Overview

The LEM can block IP addresses on firewalls. 

Environment

  • LEM All versions
  • Cisco PIX and ASA firewalls

Detail

When LEM uses the Block IP active response, it connects to the firewall over ssh or telnet and issues a shun command like this:
shun {IP_Address}
This will cause the ASA to block all traffic originating at the specified ip address.

 

 

Last modified

Tags

Classifications

Public