59-8
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter59 Configuring the Botnet Traffic Filter
Configuring the Botnet Traffic Filter
Step4 Enable traffic classification and actions for the Botnet Traffic Filter. See the “Enabling Traffic
Classification and Actions for the Botnet Traffic Filter” section on page59-11.
This procedure enables the Botnet Traffic Filter, which compares the source and destination IP address
in each initial connection packet to the IP addresses in the dynamic database, static database, DNS
reverse lookup cache, and DNS host cache, and sends a syslog message or drops any matching traffic.
Step5 (Optional) Block traffic manually based on syslog message information. See the “Blocking Botnet
Traffic Manually” section on page59-13.
If you choose not to block malware traffic automatically, you can block traffic manually by configuring
an access rule to deny traffic, or by using the shun command in the Command Line Interface tool to
block all traffic to and from a host.
Configuring the Dynamic Database
This procedure enables database updates, and also enables use of the downloaded dynamic database by
the ASA. Disabling use of the downloaded database is useful in multiple context mode so you can
configure use of the database on a per-context basis.
By default, downloading and using the dynamic database is disabled.
Prerequisites
Enable ASA use of a DNS server in the Device Management > DNS > DNS Client > DNS Lookup area.
In multiple context mode, enable DNS per context.
Detailed Steps
Step1 Enable downloading of the dynamic database.
In Single mode, choose the Configuration > Firewall > Botnet Traffic Filter > Botnet Database
pane, then check the Enable Botnet Updater Client check box.
In multiple context mode in the System execution space, choose the Configuration > Device
Management > Botnet Database pane, then check the Enable Botnet Updater Client check box.
This setting enables downloading of the dynamic database from the Cisco update server. In multiple
context mode, enter this command in the system execution space. If you do not have a database already
installed on the ASA, it downloads the database after approximately 2 minutes. The update server
determines how often the ASA polls the server for future updates, typically every hour.
Step2 (Multiple context mode only) In multiple context mode, click Apply. Then change to the context where
you want to configure the Botnet Traffic Filter by double-clicking the context name in the Device List.
Step3 In the Configuration > Firewall > Botnet Traffic Filter > Botnet Database > Dynamic Database
Configuration area, check the Use Botnet data dynamically downloaded from updater server check
box.
Step4 Click Apply.
Step5 (Optional) If you want to later remove the database from running memory, perform the following steps:
a. Disable use of the database by unchecking the Use Botnet data dynamically downloaded from
updater server check box.
b. Click Apply.