Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: How does the Block IP active response work for multiple connected firewalls?

$
0
0

It'll only broadcast the command if you've got an active response connector configured, and there might be some nuances to each firewall as to whether that matters - with Cisco IOS we do route to null, with cisco PIX/ASA it's a shun, with checkpoint it's a SAM block with a timeout, with juniper/sonicwall devices (and others I'm forgetting) it's an actual entry in the policies that gets added. It's likely up to each OS as to whether it creates a dupe or not.

 

I don't know if we have a feature request on thwack for targeting block IP responses to specific firewalls, but it's something I've heard before. Something like the way we do the "Send Popup Message" active response would work well here - if you don't specify a user, it sends to ALL connected/logged in users, but if you specify a user it only sends to that specific user.

 

The original idea was that if one site detected an attack you could protect all sites from the same attack without having to configure a bunch of block IP actions for all the different possible sites.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>