Chapter 12. Attack Guards, Intrusion Detection, and Shunning

On completion of this chapter, you will be able to perform the following tasks:

  • Identify, describe, and configure the attack guards in the PIX Firewall.

  • Define intrusion detection.

  • Describe signatures.

  • Name and identify signature classes supported by the PIX Firewall.

  • Configure the PIX Firewall to use intrusion detection system (IDS) signatures.

  • Configure the PIX Firewall for shunning.

The PIX Firewall includes basic intrusion detection system (IDS) capabilities as well as safeguards against known exploits of common services. It also has the ability to shun suspect traffic when certain conditions are met and the device is configured to do so. These capabilities have been expanded with each ...

Get CCSP Self-Study: Cisco Secure PIX Firewall Advanced (CSPFA), Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.