Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Manually Blocking and Removing a Block

Nov 26,2008 by admin

image

Manually Blocking and Removing a Block

Another option given to use with Cisco Secure IDS is to manually block, or remove a block from, an IP address. Some administrators may like this option, as it will give much more freedom to choose when and where IP Blocking takes place. This may also be an option for a Cisco Secure IDS implementation that was done quickly and has not yet been fully configured. Another reason could be Mr. Smith in payroll forgot to add your bonus to your last paycheck, (of course we don't condone this type of behavior). Whatever the reason, this process is a simple and effective method for IP Blocking.

Let's first look at manually blocking a specific IP address of a host or a network. Using the Cisco Secure Policy Manager, we need to perform the following steps:

  1. Select Tools | View Sensor Events | Database to open the Event Viewer – Database Events.

  2. Choose View | Connection Status Pane for an easier window format to view.

  3. Pick an alarm with the source IP address of the target to be blocked.

  4. From the menu bar, select Actions | Block | [Host… or Network…].

Shortly, a Shunning Hosts window will appear with the current status of this operation and if the block was successfully executed, a "Success" message will appear. This manually configured IP Block will have a default Blocking Duration of 1440 minutes, or 24 hours.

Now that we have covered how to invoke blocking manually on a host or network, let's take a look at how to remove a block from a host or network. This may be a desirable option if a critical host was not identified during the planning process of implementation, a false positive wasn't really an attack, or if a vulnerability was mitigated and the block is not needed anymore.

To remove a block, open the CSPM Event Viewer—do this the same way as when adding a block. Select the sensor which will allow us to view the block. Choose the block with the source IP address of the system or network we want to free up and select Actions | Block | [Host… or Network…]. As when implementing a manual block, a window will pop up with the current status information and a "Success" message will appear if the operation succeeded.


131 times read

Related news

» Determining the Status of the Managed Device and Blocked Addresses
by admin posted on Nov 26,2008
» The Never Block IP Addresses Setup
by admin posted on Nov 26,2008
» Preference Settings
by alperen posted on Mar 17,2010
» Configuring the Sensor to Block
by admin posted on Nov 26,2008
» Configuring Cisco IDS Blocking
by admin posted on Nov 26,2008
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author