<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block internet access on PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254549#M833178</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Small change on the above. If I dont add udp, I saw dns issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l inside-acl deny tcp host 10.10.10.1 any eq 80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l inside-acl permit tcp any any&lt;/P&gt;&lt;P&gt;access-l inside-acl permit udp any any&lt;/P&gt;&lt;P&gt;access-g inside-acl in int inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Jul 2009 20:51:36 GMT</pubDate>
    <dc:creator>techtips03</dc:creator>
    <dc:date>2009-07-30T20:51:36Z</dc:date>
    <item>
      <title>Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254539#M833168</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 506E with 6.3(5) version and I would like to know if I can block internet access to certain users and allow access to some users on the same LAN. I have a SBS server on the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254539#M833168</guid>
      <dc:creator>techtips03</dc:creator>
      <dc:date>2019-03-11T15:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254540#M833169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you have static IP addresses or DHCP on the LAN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 15:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254540#M833169</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-07-17T15:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254541#M833170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807349e7.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 16:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254541#M833170</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-07-17T16:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254542#M833171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have DHCP on the LAN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 16:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254542#M833171</guid>
      <dc:creator>techtips03</dc:creator>
      <dc:date>2009-07-17T16:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254543#M833172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would have to do it individually for the IP addresses that you want to block port 80 and allow the rest. You can use dhcp mac address reservation so, these denied hosts will always get the same ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l inside-acl deny tcp host 10.10.10.1 any eq 80&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.--&amp;gt; add all the denies&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;access-l inside-acl  permit tcp any any eq 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-g inside-acl in int inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 17:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254543#M833172</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-07-17T17:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254544#M833173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Sankar. When you say dhcp mac reservation, do you mean assigning IP address to MAC on the dhcp server so they can get the same IPs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 20:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254544#M833173</guid>
      <dc:creator>techtips03</dc:creator>
      <dc:date>2009-07-17T20:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254545#M833174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly. Yes. Reserving an IP address for a MAC address on the dhcp server so, these computers will consistently get the same IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 21:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254545#M833174</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-07-17T21:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254546#M833175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One option is running AAA and Cut through proxy.  The drawback is that it will ask each user to log in.  The Pix cannot tell who the user is from the packets.  There is no user information in them.  The SBS should be able to function as a Radius server and perform the authentication.  I would consider the configuration and intermediate level task.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Jul 2009 00:53:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254546#M833175</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2009-07-18T00:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254547#M833176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. What if the users move between 2 different locations which are on VPN? If DHCP server is at both locations I think I can still map their MAC to IPs at both locations. But if the remote location is getting DHCP from the main location on the VPN then this setup will not work right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jul 2009 16:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254547#M833176</guid>
      <dc:creator>techtips03</dc:creator>
      <dc:date>2009-07-22T16:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254548#M833177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if they move with the machines - you have an issues.  The you need to think about proxy cut-thru and a radius server to authenticate users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jul 2009 17:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254548#M833177</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-07-22T17:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Block internet access on PIX</title>
      <link>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254549#M833178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Small change on the above. If I dont add udp, I saw dns issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l inside-acl deny tcp host 10.10.10.1 any eq 80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l inside-acl permit tcp any any&lt;/P&gt;&lt;P&gt;access-l inside-acl permit udp any any&lt;/P&gt;&lt;P&gt;access-g inside-acl in int inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2009 20:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-internet-access-on-pix/m-p/1254549#M833178</guid>
      <dc:creator>techtips03</dc:creator>
      <dc:date>2009-07-30T20:51:36Z</dc:date>
    </item>
  </channel>
</rss>

