<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX DNS/Hostname Blocking/Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172006#M605824</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   I see.  So what is the best way to deal with restricting access to DNS names that resolve to multiple and/or dynamic IP's?  &lt;/P&gt;&lt;P&gt;   Are there any alternatives  to manually maintaining a host file/access list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Thanks for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-P &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 May 2003 23:43:11 GMT</pubDate>
    <dc:creator>woodp</dc:creator>
    <dc:date>2003-05-19T23:43:11Z</dc:date>
    <item>
      <title>PIX DNS/Hostname Blocking/Configuration</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172004#M605820</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;   I started out on a mission to block instant messaging- (AIM, Yahoo, MSN)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  To avoid an endless list of IP's, I was planning on blocking the login servers by DNS name.  I soon discovered that our PIX cannot resolve any hostnames.  It can ping to the outside world just fine, but it cannot ping any hostname, including itself.  DNS server configuration seems to be a different beast altogether on PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Am I missing something?  How should I go about making this possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Thanks!&lt;/P&gt;&lt;P&gt;                         -Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some brief info: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco PIX Firewall Version 6.2(2)&lt;/P&gt;&lt;P&gt;Cisco PIX Device Manager Version 2.1(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   PIX-525, 256 MB RAM, CPU Pentium III 600 MHz&lt;/P&gt;&lt;P&gt;Flash E28F128J3 @ 0x300, 16MB&lt;/P&gt;&lt;P&gt;BIOS Flash AM29F400B @ 0xfffd8000, 32KB &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172004#M605820</guid>
      <dc:creator>woodp</dc:creator>
      <dc:date>2020-02-21T06:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS/Hostname Blocking/Configuration</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172005#M605823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, you are right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unlike router, you cannot configure PIX to use any DNS server for name ressolution.  But, what you can do though is use the following command to name your ips:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name &lt;IP_ADDRESS&gt; &lt;NAME&gt;&lt;/NAME&gt;&lt;/IP_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if you define, name &lt;A class="jive-link-custom" href="http://www.test.com" target="_blank"&gt;www.test.com&lt;/A&gt; 10.1.1.1 then you can ping this address by the &lt;A class="jive-link-custom" href="http://www.test.com." target="_blank"&gt;www.test.com.&lt;/A&gt;  No need to use the ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, defining a seperate dns server for name ressolution is not possible on the PIX Firewall.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this answers your question.  Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2003 22:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172005#M605823</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-05-19T22:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS/Hostname Blocking/Configuration</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172006#M605824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   I see.  So what is the best way to deal with restricting access to DNS names that resolve to multiple and/or dynamic IP's?  &lt;/P&gt;&lt;P&gt;   Are there any alternatives  to manually maintaining a host file/access list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Thanks for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-P &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2003 23:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172006#M605824</guid>
      <dc:creator>woodp</dc:creator>
      <dc:date>2003-05-19T23:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS/Hostname Blocking/Configuration</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172007#M605825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best and only solution is to use url filtering.  You can filter the web traffic based on domain name, ip addresses or specific keyword etc... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the a link that explains:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008008c103.html#xtocid9" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008008c103.html#xtocid9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the newer version of Pix code, this feature has been improved a lot.  Please refer to the command reference of the version you are running.   PIX can support web sense and N2H2 url filtering server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unlike NBAR feature on the router, PIX cannot do similiar things like packet marking and dropping rather it relies on external web filtering servers like Web Sense or N2H2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps !  Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2003 02:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-hostname-blocking-configuration/m-p/172007#M605825</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-05-20T02:48:17Z</dc:date>
    </item>
  </channel>
</rss>

