Firewall Wizards mailing list archives
Re: CSA Question
From: "Kristian Erik Hermansen" <kristian.hermansen () gmail com>
Date: Tue, 21 Aug 2007 19:29:32 -0400
On 8/21/07, Carric Dooley <carric () com2usa com> wrote:
I have been looking thru the Cisco site and I'm wondering if anyone knows if you can configure the CSA to disable network interfaces, for instance if it's attcked, or shut down.
I work on the Cisco Security Agent team, and I do know that there is a "Network Lock" mode, which will disallow all new connections. I believe we also added some new features for disabling wireless devices in a recent release. I am unsure if there is a way to define a rule such as "if rootkit is detected, disable all interfaces". I am cc'ing Marcus Gavel who who should be able to get you an answer... -- Kristian Erik Hermansen _______________________________________________ firewall-wizards mailing list firewall-wizards () listserv icsalabs com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: CSA Question bobw () avantsystems com (Aug 22)
- <Possible follow-ups>
- Re: CSA Question Kristian Erik Hermansen (Aug 22)
- Re: CSA Question Marcus Gavel (mgavel) (Aug 22)