If this is applied inbound to the interface that is the workstation's default gateway, this will block that single workstation from sending traffic to or through the router.
If you are using managed switches the easiest way would be to shutdown that switch port or simply unplug the cable. If you are using DHCP and that PC gets a different address the next time it signs in, then blocking one single IP would not work for you.
Our policy is to shut down the port the infected PC is connected to. If the closeset port we have control of is a office or building port we shut that down. Better to cut off 100 users that infect the entire 1500.
We put in an emergency call to the office manager and have them unplug and lock down (physically) the offending PC then we re-enable the office/building and do a complete re-scan.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.