Cisco Cisco ASA 5555-X Adaptive Security Appliance 安装指南

下载
页码 16
14
 
Note
For VMware DVS and Bare Metal (in bridged mode), two attributes (filters) are automatically 
created when an end point is quarantined, one attribute for the IP address and one attribute 
for the MAC address. Therefore, to remove the quarantine, you must delete both attributes.
Step 4
If the quarantine was not successful (no uSeg attributes were created), you can manually 
quarantine the IP address, as described in the next section.
Manually Quarantine an IP Address
If the quarantine was unsuccessful, optionally complete the following steps to manually quarantine the 
IP address.
Step 1
Identify the IP address of the end point that you want to quarantine.
a.
On the Analysis tab on the FMC GUI, select the Correlation > Status sub-tab.
b.
On the Remediation Status page, find the time stamp of entry for the unsuccessful quarantine 
and make note of the source IP address.
c.
On the Operations tab, select EP Tracker, enter the IP address, and press Enter.
d.
If no information is displayed, the end point cannot be quarantined. If more than one IP 
address is displayed, look for the one in the offending tenant.
Step 2
If you can identify the EPG of the end point that you want to quarantine, create a uSeg EPG 
attribute corresponding to this end point.
a.
On the Tenants tab of the APIC GUI, use the information from Step 1 to find the EPG and 
make note of the bridge domain.
b.
Expand the EPG and make note of the domain profile name.
c.
On the Tenants tab, expand the Application Profiles, and right-click uSeg EPG.
d.
Enter a name for the uSeg EPG, in this format: “quarantine-EPG_name_of_the_EP.
e.
Select the bridge domain of the EPG from Step 2a.
f.
Add an IP filter attribute by clicking the plus sign on lower right and entering the IP address 
for the name and filter. 
g.
Click Next Step and select the same domain profile from step 2b.
h.
Set the Deployment Immediacy to Immediate.
i.
Click Update and then click Finish.