<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking access inside by domain in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087897#M893487</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me make it clear for you.  Pix/ASA can not&lt;/P&gt;&lt;P&gt;do this.  The domain features are available&lt;/P&gt;&lt;P&gt;on Sidewinder and Checkpoint firewalls but sadly&lt;/P&gt;&lt;P&gt;not available in Pix/ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Nov 2008 22:02:47 GMT</pubDate>
    <dc:creator>cisco24x7</dc:creator>
    <dc:date>2008-11-18T22:02:47Z</dc:date>
    <item>
      <title>Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087887#M893477</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a pix 535 and was wondering if there was a way to block access in to a particular website by domain such as .edu or .gov.  Any help would be great.  Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087887#M893477</guid>
      <dc:creator>techiegrl</dc:creator>
      <dc:date>2019-03-11T14:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087888#M893478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are running  version code 7.2.x and above  you can  block urls by domain using MPF, have a look here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940c5a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940c5a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If code 6.x you would probably need 3rd party to realy fitering urls, have a look here.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008088517b.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008088517b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 01:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087888#M893478</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-11-18T01:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087889#M893479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi and thanks.  At first look it seems like this is for outgoing requests.  could I use the same for incoming requests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 17:28:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087889#M893479</guid>
      <dc:creator>techiegrl</dc:creator>
      <dc:date>2008-11-18T17:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087890#M893480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi and thanks.  At first look it seems like this is for outgoing requests.  could I use the same for incoming requests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 17:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087890#M893480</guid>
      <dc:creator>techiegrl</dc:creator>
      <dc:date>2008-11-18T17:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087891#M893481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Stefanie,&lt;/P&gt;&lt;P&gt;  To which users do you want to block these web domains? &lt;/P&gt;&lt;P&gt;  Jorge's answer is on spot, can be applied in any way you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 18:07:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087891#M893481</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-11-18T18:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087892#M893482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance, let's say that I wanted to only allow .mil users access to my website.  Can I use the document in question for ver. 7.2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 18:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087892#M893482</guid>
      <dc:creator>techiegrl</dc:creator>
      <dc:date>2008-11-18T18:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087893#M893483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not clear on "only allow .mil users access to my website"&lt;/P&gt;&lt;P&gt;  So you have a webserver we are OK here, but what is a .mil user? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 18:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087893#M893483</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-11-18T18:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087894#M893484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Someone on a .mil domain.  Yes, we have several webservers, but wanted to only allow access to users coming from a certain domain name. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 18:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087894#M893484</guid>
      <dc:creator>techiegrl</dc:creator>
      <dc:date>2008-11-18T18:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087895#M893485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stefanie,&lt;/P&gt;&lt;P&gt;  Let me make a correction first on the logical design.&lt;/P&gt;&lt;P&gt;  A connection attempt from a source can contain source IP, source MAC, source port, username&amp;amp;password (if implemented), flags (SYN, SYN+ACK etc). Source domain is not an option here. Yet, the only domain name that you can get while qureying an IP address to learn its domain will be the one assigned by the ISP (something random). Thats why source domain is not a criteria to match and apply restrictions on. Thats why you cant have a workaround with a third party in my opinion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 18:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087895#M893485</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-11-18T18:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087896#M893486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now, i'm a little confused.  I have a Sidewinder on another one of my networks, and I can select .gov or .mil as a source domain to access a webserver on my network.  I am trying to do the same via my Pix 535.  We are trying to lock down access to our websites from certain domains and I was trying to get it to work from the pix.  So I don't want to block outgoing, but incoming, and without knowing every IP associated with the .gov domain, I was hoping for an easy way to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source (.gov) dest. (mywebsite) port (443)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 21:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087896#M893486</guid>
      <dc:creator>techiegrl</dc:creator>
      <dc:date>2008-11-18T21:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087897#M893487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me make it clear for you.  Pix/ASA can not&lt;/P&gt;&lt;P&gt;do this.  The domain features are available&lt;/P&gt;&lt;P&gt;on Sidewinder and Checkpoint firewalls but sadly&lt;/P&gt;&lt;P&gt;not available in Pix/ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 22:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087897#M893487</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-11-18T22:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking access inside by domain</title>
      <link>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087898#M893488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 22:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-access-inside-by-domain/m-p/1087898#M893488</guid>
      <dc:creator>techiegrl</dc:creator>
      <dc:date>2008-11-18T22:06:23Z</dc:date>
    </item>
  </channel>
</rss>

