Open for Voting

Block IP active response: Select individual or multiple connected firewalls for active response

It would be useful if the Block IP action worked the way the "Send Popup Message" active response does. In our current configuration one of our firewalls will automatically block attacker IP addresses but we would like to then update the rest of the firewalls with those blocked addresses. If the block IP command does a blast to all active response connected firewalls this will likely cause a double entry on the firewall that initially blocked the attack. Being able to select individual or multiple firewalls to block when an attack is detected would be very useful as not all the firewalls connected need to take the same action.