<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to deny user use the ip address of PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615621#M1029123</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I feel the best practice for this case is to put the PIX in a separate VLAN. The Proxy can be in the user VLAN. This will solve all the issues, as user cannot configure the PIX IP on their PCs and get access to network. PCs will have the def-gateway to Proxy, the proxy will have def-gw at VLAN IP, and a def route will be there on the switch to the PIX. Thats it.&lt;/P&gt;&lt;P&gt;C if this suggestion helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Jan 2007 10:18:44 GMT</pubDate>
    <dc:creator>sarkarpritam</dc:creator>
    <dc:date>2007-01-12T10:18:44Z</dc:date>
    <item>
      <title>How to deny user use the ip address of PIX</title>
      <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615614#M1029097</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very new with this, all of my users's PC gateway is assigned to IP 172.16.1.5 (Proxy server).. and the gateway of The Proxy Server is assigned to PIX 172.16.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the users knew the IP address of PIX then they will set their gateway to PIX's IP Address then they able to go to the internet without proxy server, this is the part that I want to deny &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could any body please help how to deal with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Winanjaya&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615614#M1029097</guid>
      <dc:creator>winanjaya</dc:creator>
      <dc:date>2019-03-11T09:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to deny user use the ip address of PIX</title>
      <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615615#M1029102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can handle this by, including an ACL in the firewall which allows outbound HTTP access only for the proxy server IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then the users wouldn't be able to browse through the firewall, they have point to the proxy server to get internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-VJ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 07:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615615#M1029102</guid>
      <dc:creator>vijayasankar</dc:creator>
      <dc:date>2007-01-12T07:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to deny user use the ip address of PIX</title>
      <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615616#M1029107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very new with this, could you pls give me an example?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Winanjaya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 07:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615616#M1029107</guid>
      <dc:creator>winanjaya</dc:creator>
      <dc:date>2007-01-12T07:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to deny user use the ip address of PIX</title>
      <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615617#M1029111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply the following ACL on the inside interface of your PIX in configuration mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit tcp host 172.16.1.5 any eq www&lt;/P&gt;&lt;P&gt;access-list inside deny tcp any any eq www&lt;/P&gt;&lt;P&gt;access-list inside permit ip any any&lt;/P&gt;&lt;P&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Save with: write mem and also issue: clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above ACL will only allow your proxy server to browse the internet and deny anything else. Now your users MUST&lt;/P&gt;&lt;P&gt;point their browser to the proxy server!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps and please rate posts!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 07:50:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615617#M1029111</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2007-01-12T07:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to deny user use the ip address of PIX</title>
      <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615618#M1029114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how about for ftp, https and any other internet services.. pls advise&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;P&gt;Winanjaya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 08:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615618#M1029114</guid>
      <dc:creator>winanjaya</dc:creator>
      <dc:date>2007-01-12T08:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to deny user use the ip address of PIX</title>
      <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615619#M1029117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using proxy also for FTP and HTTPS add those services to access-list&lt;/P&gt;&lt;P&gt;access-list inside permit tcp host 172.16.1.5 any eq www&lt;/P&gt;&lt;P&gt;access-list inside permit tcp host 172.16.1.5 any eq ftp&lt;/P&gt;&lt;P&gt;access-list inside permit tcp host 172.16.1.5 any eq 443&lt;/P&gt;&lt;P&gt;access-list inside deny tcp any any eq www&lt;/P&gt;&lt;P&gt;access-list inside deny tcp any any eq ftp&lt;/P&gt;&lt;P&gt;access-list inside deny tcp any any eq 443&lt;/P&gt;&lt;P&gt;access-list inside permit ip any any&lt;/P&gt;&lt;P&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 09:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615619#M1029117</guid>
      <dc:creator>m.sir</dc:creator>
      <dc:date>2007-01-12T09:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to deny user use the ip address of PIX</title>
      <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615620#M1029121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Winanjaya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 09:35:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615620#M1029121</guid>
      <dc:creator>winanjaya</dc:creator>
      <dc:date>2007-01-12T09:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to deny user use the ip address of PIX</title>
      <link>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615621#M1029123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I feel the best practice for this case is to put the PIX in a separate VLAN. The Proxy can be in the user VLAN. This will solve all the issues, as user cannot configure the PIX IP on their PCs and get access to network. PCs will have the def-gateway to Proxy, the proxy will have def-gw at VLAN IP, and a def route will be there on the switch to the PIX. Thats it.&lt;/P&gt;&lt;P&gt;C if this suggestion helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 10:18:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-deny-user-use-the-ip-address-of-pix/m-p/615621#M1029123</guid>
      <dc:creator>sarkarpritam</dc:creator>
      <dc:date>2007-01-12T10:18:44Z</dc:date>
    </item>
  </channel>
</rss>

