A-25
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix A Intrusion Detection System Architecture
System Components
Caution
The PIX Firewall does not support connection blocking of hosts. When a
connection block is applied, the PIX Firewall treats it like an unconditional block.
The PIX Firewall also does not support network blocking. NAC never tries to
apply a network block to a PIX Firewall.
Blocking with the PIX Firewall
This sections describes the PIX Firewall and blocking.
This section contains the following topics:
•
The shun Command, page A-25
•
The PIX Firewall and AAA, page A-26
•
Address Translation and Blocking, page A-26
The shun Command
NAC performs blocks on the PIX Firewall using the shun command. The shun
command has the following formats:
•
To block an IP address:
shun srcip [
destip sport dport
[
port
]]
•
To unblock an IP address:
no shun ip
•
To clear all blocks:
clear shun
•
To show active blocks or to show the global address that was actually
blocked:
show shun [
ip_address
]
NAC uses the response to the show shun command to determine whether the
block was performed.
The shun command does not replace existing ACLs, conduits, or outbound
commands, so there is no need to cache the existing PIX Firewall configuration,
nor to merge blocks into the PIX configuration.
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...