On Cisco Pix and ASA Firewalls, there are many different ways to block / drop traffic.
The most obvious way would be to create an Access Control List (ACLs) to block traffic from a specific ip address. This method can be particularly useful as you would be able to control which ip addresses you want to traverse your network.
Another key method to drop any connections already created would be by using the shun command. This is a fantastic command which will help to combat any security threats immediately. Using this, you can drop traffic for tcp, udp or all protocols. See example below:
For this example I will use the IP address 5.5.5.5 as a threat which needs to be dropped immediately. I will show you a method for dropping specific tcp traffic to 6.6.6.6 followed by dropping any form of traffic to any destination.
Example 1: shun 5.5.5.5 6.6.6.6 3389 tcp
This will drop all tcp 3389 connections from 5.5.5.5 to 6.6.6.6 only. To further this, you could be vague and not specify the port, as below:
Example 2: shun 5.5.5.5 6.6.6.6 tcp
This will drop all tcp connections from 5.5.5.5 to 6.6.6.6 only.
Example 3 shows how you could utilise this to drop all traffic from 5.5.5.5. This is irrelevant of protocol or destination.
Example 3: shun 5.5.5.5
The reverse / back out of any of the above commands would be to simply place a “no” at the front.
Hope you find this useful!
Comments
Usman,
Great post and very well illustrated. Keep up the good work. Need more blogs like these.
Did you know you can also when you want to remove all shunning on the box, don’t reboot, you can issue ‘clear shun’ command.