
19-6
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 19 Intercepting and Responding to Network Attacks
Protecting Your Network Against Specific Attacks
If you enter only the source IP address, then all future connections are shunned; existing connections
remain active.
To drop an existing connection, as well as blocking future connections from the source IP address, enter
the destination IP address, source and destination ports, and the protocol. By default, the protocol is 0
for IP.
For multiple context mode, you can enter this command in the admin context, and by specifying a
VLAN ID that is assigned to a subinterface in other contexts, you can shun the connection in other
contexts.
Step 3 To remove the shun, enter the following command:
hostname(config)# no shun
src_ip
[vlan
vlan_id
]
Kommentare zu diesen Handbüchern