<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Selective Java applet blocking by external address with PIX? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/selective-java-applet-blocking-by-external-address-with-pix/m-p/172020#M606847</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw that, but I can't translate that into what I want to do.  Maybe I'm missing something.&lt;/P&gt;&lt;P&gt;What I want to do is to deny Java applets from all foreign hosts except fro those I define as friendly.  Using CBAC, I'd set up a java access list along these lines:&lt;/P&gt;&lt;P&gt;access-list XX permit 12.0.3.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list XX deny any &lt;/P&gt;&lt;P&gt;Which would allow Java applets from 12.0.3.0/24 but deny them from everyone else.&lt;/P&gt;&lt;P&gt;If I could use the filter java command to filter all java *except* certain stuff, that'd be perfect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Apr 2003 22:44:55 GMT</pubDate>
    <dc:creator>bhockenhull</dc:creator>
    <dc:date>2003-04-16T22:44:55Z</dc:date>
    <item>
      <title>Selective Java applet blocking by external address with PIX?</title>
      <link>https://community.cisco.com/t5/network-security/selective-java-applet-blocking-by-external-address-with-pix/m-p/172018#M606843</link>
      <description>&lt;P&gt;I'm trying to implement Java applet blocking on my PIX, and I'm looking for a way to be more selective about how i do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the documentation, I can permit certain internal addresses to get Java applets from the outside, but it doesn't seem that I can permit all internal addresses to get Java applets only from certain external addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can do this (but would prefer not to) at my border router with CBAC using access lists, but the same functionality doesn't seem to be present in the PIX.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:41:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/selective-java-applet-blocking-by-external-address-with-pix/m-p/172018#M606843</guid>
      <dc:creator>bhockenhull</dc:creator>
      <dc:date>2020-02-21T06:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Java applet blocking by external address with PIX?</title>
      <link>https://community.cisco.com/t5/network-security/selective-java-applet-blocking-by-external-address-with-pix/m-p/172019#M606845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you read this:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/df.htm#1039734" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/df.htm#1039734&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the above document, you can specify either internal and/or external addresses in the "filter java" command. Did you try it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is your pix OS version?&lt;/P&gt;&lt;P&gt;What is the exact command that you try?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yizhar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2003 22:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/selective-java-applet-blocking-by-external-address-with-pix/m-p/172019#M606845</guid>
      <dc:creator>yizhar</dc:creator>
      <dc:date>2003-04-16T22:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Selective Java applet blocking by external address with PIX?</title>
      <link>https://community.cisco.com/t5/network-security/selective-java-applet-blocking-by-external-address-with-pix/m-p/172020#M606847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw that, but I can't translate that into what I want to do.  Maybe I'm missing something.&lt;/P&gt;&lt;P&gt;What I want to do is to deny Java applets from all foreign hosts except fro those I define as friendly.  Using CBAC, I'd set up a java access list along these lines:&lt;/P&gt;&lt;P&gt;access-list XX permit 12.0.3.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list XX deny any &lt;/P&gt;&lt;P&gt;Which would allow Java applets from 12.0.3.0/24 but deny them from everyone else.&lt;/P&gt;&lt;P&gt;If I could use the filter java command to filter all java *except* certain stuff, that'd be perfect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2003 22:44:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/selective-java-applet-blocking-by-external-address-with-pix/m-p/172020#M606847</guid>
      <dc:creator>bhockenhull</dc:creator>
      <dc:date>2003-04-16T22:44:55Z</dc:date>
    </item>
  </channel>
</rss>

