Submit a ticketCall us

Looking to compare latest NPM features with previous versions of NPM?
The NPM new feature summary offers a comparison of new features and improvements offered with this release.

 

Home > Success Center > Log & Event Manager (LEM) > How does Cisco Block IP active response work

How does Cisco Block IP active response work

Table of contents

Updated March 10, 2017

Overview

The LEM can block IP addresses on firewalls. 

Environment

  • LEM All versions
  • Cisco PIX and ASA firewalls

Detail

When LEM uses the Block IP active response, it connects to the firewall over ssh or telnet and issues a shun command like this:
shun {IP_Address}
This will cause the ASA to block all traffic originating at the specified ip address.

 

 

Last modified
17:08, 9 Mar 2017

Tags

Classifications

Public