<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting LAN Internet Acess in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656726#M1028462</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;10.9.3.11 would not be included in 10.9.11.0/24...maybe a typo on your part&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Jan 2007 18:54:17 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-01-19T18:54:17Z</dc:date>
    <item>
      <title>Restricting LAN Internet Acess</title>
      <link>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656723#M1028459</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My set up is bassically&lt;/P&gt;&lt;P&gt;internet-router-PIX-router-switch&lt;/P&gt;&lt;P&gt;off the switch I have multiple LANS&lt;/P&gt;&lt;P&gt;of which I only want one segment to be able to get out totaly unrestricted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the basic implied rule I can get out to the internet fien and dandy. But when i try to restrict it to one LAN I lose my ability to surf.&lt;/P&gt;&lt;P&gt;The ACL I am trying to use is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSIDE permit ip 10.9.11.0 255.255.255.0 any &lt;/P&gt;&lt;P&gt;access-group INSIDE in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would think this would allow the LAN out but I am no longer able to surf once it's applied. I am new to the PIX, so i am sure it is something simple I am missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Concrete&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656723#M1028459</guid>
      <dc:creator>Concrete_</dc:creator>
      <dc:date>2019-03-11T09:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting LAN Internet Acess</title>
      <link>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656724#M1028460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you clarify. Are you saying that users on the 10.9.11.0/24 network can no longer access the internet or is it the users on other lans. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that there is an implicit deny on the end of any access-list so that access-list you have applied will allow 10.9.11.0/24 users unrestricted access out but will deny any other users getting out at all. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 17:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656724#M1028460</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-19T17:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting LAN Internet Acess</title>
      <link>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656725#M1028461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sorry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that when I add the rule above, I lose all access from my 10.9.11.0/24 network. I was expecting to lose access in other subnets, but I don't know why 10.9.3.11 loses it to. From what I understand the rule should allow 10.9.11.0/24 to do what it wants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Concrete&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 18:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656725#M1028461</guid>
      <dc:creator>Concrete_</dc:creator>
      <dc:date>2007-01-19T18:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting LAN Internet Acess</title>
      <link>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656726#M1028462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;10.9.3.11 would not be included in 10.9.11.0/24...maybe a typo on your part&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 18:54:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656726#M1028462</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-01-19T18:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting LAN Internet Acess</title>
      <link>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656727#M1028463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yah sorry, it was a typo. Anywho I figured it out, it tooks a while to clue in that the internal DNS wasn't going to be able to get out with the new rule. So I just had to allow access out for it as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help &lt;/P&gt;&lt;P&gt;Concrete &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 19:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restricting-lan-internet-acess/m-p/656727#M1028463</guid>
      <dc:creator>Concrete_</dc:creator>
      <dc:date>2007-01-19T19:22:38Z</dc:date>
    </item>
  </channel>
</rss>

