RE: [nsp] How to block Nimda in PIX or router

From: kevin graham (kgraham@dotnetdotcom.org)
Date: Wed Jan 16 2002 - 19:51:07 EST


> It cleans only http traffic, right?

Yes.

> I have a big problem actually. I big network with a
> central Cisco Switch 2948. Nimda is spread for all the network.
> How do I filter this internal network traffic to stop NIMDA dissemination
> through disk sharing?

Is it being spread via disk sharing, or http running around on the
internal network? If its actually via CIFS/SMB *shrug* talk to McAfee and
such ilk.. Otherwise, you'll need a l3 switch (is that a 2948G-L3?) to
apply those policies (though nbar, if supported at all, will probably
destroy any of the fixed-config switches with any kind of noteworthy
utilization).

..kg..



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:13:29 EDT