Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Malicious IP Profile

Want to summarize with AI?

Log in

Learn how a Malicious IP Profile helps protect cloud traffic from known malicious addresses identified by Cisco Talos threat intelligence.


Additional security protections can be enabled to prevent communication from and to known malicious IPs. These malicious IPs are defined and powered by Cisco Talos, and integrated into Multicloud Defense as a security profile ruleset. The ruleset is updated frequently as updates are made available by Talos. The updates can be either dynamically or manually applied to a policy ruleset using the automatic update configuration or manual update configuration. For more information, see Create a Malicious IP Profile.

Note

Malicious IP are identified by Talos based on various learned behavior:

  • Malicious attackers identified from web honeypots

  • Botnet C&C (command and control) hosts

  • TOR exit nodes

  • Other learned behavior.


Create a Malicious IP Profile

Use the following procedure to create a malicious IP profile:

Procedure

1.

Navigate to Policies > Profiles > Malicious IPs.

2.

Click Create.

3.

Provide a unique Profile Name.

4.

(Optional) Enter a Description. This can help differentiate between other profiles with similar names.

5.

Check the box to enable IP Reputation.

6.

Choose a ruleset version from the drop-down menu:

  • Manual - The selected ruleset version is used by the Multicloud Defense datapath engine on all gateways which use this profile. The profile will not be automatically updated to newer ruleset versions.

  • Automatic - Select the number of days to delay the update, after the ruleset version is published by Multicloud Defense. New rulesets are published frequently by Multicloud Defense. The gateways using this profile are automatically updated to the latest ruleset version which is N days or older, where N is the "delay by days" argument selected from the dropdown. For example, if you select to delay the deployment by 5 days on Jan 10, 2021, the Multicloud Defense controller will select a ruleset version which was published on Jan 5th or before. Note that Multicloud Defense may not publish on certain days if internal testing with that ruleset version fails.

7.

Click Save.

What to do next

Attach the profile to a policy rule set. See Rule Sets and Rule Set Groups for more information.


IP Reputation

The IP reputation checkbox is used as a means to enable or disable the profile. When checked and the profile is attached to a policy ruleset, malicious IP protection will be enforced. When unchecked and the profile is attached to policy rules, malicious IP protection will not be enforced. Our recommendation is to always check the IP reputation checkbox. If you want to disable the malicious IP profile, then remove its association from the policy rules rather than uncheck the checkbox.