<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX feature in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-feature/m-p/571783#M498545</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Split tunneling feature will fulfil your requirement&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Aug 2006 17:43:58 GMT</pubDate>
    <dc:creator>bwalchez</dc:creator>
    <dc:date>2006-08-11T17:43:58Z</dc:date>
    <item>
      <title>PIX feature</title>
      <link>https://community.cisco.com/t5/network-security/pix-feature/m-p/571782#M498544</link>
      <description>&lt;P&gt;I have 2 groups of users: Management and Staff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are the restrictions&lt;/P&gt;&lt;P&gt;Management:- NO access to VPN, Allow Surfing Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Staff:- Access to VPN only, no other internet access allowed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does a Cisco Pix allow me to do that? If so, by what feature? ACL or etc?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-feature/m-p/571782#M498544</guid>
      <dc:creator>J_Vansen_S</dc:creator>
      <dc:date>2020-02-21T09:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: PIX feature</title>
      <link>https://community.cisco.com/t5/network-security/pix-feature/m-p/571783#M498545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Split tunneling feature will fulfil your requirement&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2006 17:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-feature/m-p/571783#M498545</guid>
      <dc:creator>bwalchez</dc:creator>
      <dc:date>2006-08-11T17:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: PIX feature</title>
      <link>https://community.cisco.com/t5/network-security/pix-feature/m-p/571784#M498546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Split-tunneling allows for certain traffic to be routed over the VPN and certain traffic to be routed out an interface unencrypted.  This will not overall solve your problem.  You would need to still apply ACLs upstream on the PIX to block Internet access for Staff and Management the split-tunnel wouldn't even apply.  Static acls isn't scalable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The feature you want to look at is AAA for Network Access (legacy IOS firewall it was called Auth-Proxy).  This can be integrated with your Windows AD or RADIUS, etc.  This can be further enhanced with Cisco ACS to use User downloaded acls (which can be specified at a group level).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link, look for the section Applying AAA for Network Access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/application/pdf/en/us/guest/products/ps6120/c2001/ccmigration_09186a0080641f89.pdf" target="_blank"&gt;http://www.cisco.com/application/pdf/en/us/guest/products/ps6120/c2001/ccmigration_09186a0080641f89.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate any helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2006 19:31:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-feature/m-p/571784#M498546</guid>
      <dc:creator>fred.s.mollenkopf</dc:creator>
      <dc:date>2006-08-11T19:31:35Z</dc:date>
    </item>
  </channel>
</rss>

