<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block users' access to websites in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060198#M915885</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PIX 506E running IOS 6.3. My client can not afford to buy Websense or any web filtering software at the moment and he wants to block access to only three web sites at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how best to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if my client wants to block access to the following web sites:&lt;/P&gt;&lt;P&gt;a.) &lt;A class="jive-link-custom" href="http://www.yahoo.com" target="_blank"&gt;www.yahoo.com&lt;/A&gt; with IP address 87.248.113.14&lt;/P&gt;&lt;P&gt;b.) &lt;A class="jive-link-custom" href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; with IP address 66.249.93.99&lt;/P&gt;&lt;P&gt;and c.) &lt;A class="jive-link-custom" href="http://www.monsterjobs.com" target="_blank"&gt;www.monsterjobs.com&lt;/A&gt; with IP address 208.71.197.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What will be the best way to block users from accessing these web sites on PIX 506E running IOS 6.3(5).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:21:03 GMT</pubDate>
    <dc:creator>a.ajiboye</dc:creator>
    <dc:date>2019-03-11T13:21:03Z</dc:date>
    <item>
      <title>Block users' access to websites</title>
      <link>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060198#M915885</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PIX 506E running IOS 6.3. My client can not afford to buy Websense or any web filtering software at the moment and he wants to block access to only three web sites at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how best to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if my client wants to block access to the following web sites:&lt;/P&gt;&lt;P&gt;a.) &lt;A class="jive-link-custom" href="http://www.yahoo.com" target="_blank"&gt;www.yahoo.com&lt;/A&gt; with IP address 87.248.113.14&lt;/P&gt;&lt;P&gt;b.) &lt;A class="jive-link-custom" href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; with IP address 66.249.93.99&lt;/P&gt;&lt;P&gt;and c.) &lt;A class="jive-link-custom" href="http://www.monsterjobs.com" target="_blank"&gt;www.monsterjobs.com&lt;/A&gt; with IP address 208.71.197.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What will be the best way to block users from accessing these web sites on PIX 506E running IOS 6.3(5).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060198#M915885</guid>
      <dc:creator>a.ajiboye</dc:creator>
      <dc:date>2019-03-11T13:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Block users' access to websites</title>
      <link>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060199#M915887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I don't think this is possible with ios 6.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an example of blocking websites/url with  MPF(Modular Policy Framework) on ios 7.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940c5a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940c5a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 08:44:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060199#M915887</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2008-07-28T08:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Block users' access to websites</title>
      <link>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060200#M915888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;inbound access-list on the inside interface...&lt;/P&gt;&lt;P&gt;you would have 3 deny statements to deny all ip traffic goign to those IP's (or just tcp/80) and then a permit ip any any at the end.&lt;/P&gt;&lt;P&gt;keep in mind, blocking IP's is less reliable than a true url-filtering solution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 09:32:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060200#M915888</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-07-28T09:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Block users' access to websites</title>
      <link>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060201#M915889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Blocking with Access-lists will only help when the IP address for the webiste &lt;A class="jive-link-custom" href="http://www.xyz.com" target="_blank"&gt;www.xyz.com&lt;/A&gt; is fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in case of a website like &lt;A class="jive-link-custom" href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; there are various IP's which may not be feasible to block using access-lists.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 10:12:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060201#M915889</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2008-07-28T10:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Block users' access to websites</title>
      <link>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060202#M915890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your suggestions. I seem can't get my PIX to block access to those site. Find below my PIX config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;testpix(config)# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;hostname testpix&lt;/P&gt;&lt;P&gt;domain-name ciscopix.com&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names         &lt;/P&gt;&lt;P&gt;object-group network web_servers &lt;/P&gt;&lt;P&gt;  description Blocks access to Yahoo! web sites (yahoo.com &amp;amp; uk.yahoo.com)&lt;/P&gt;&lt;P&gt;  network-object host 87.248.113.14 &lt;/P&gt;&lt;P&gt;  network-object host 217.146.186.51 &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 192.168.241.45 eq 3389 &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 192.168.241.45 eq www &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 192.168.241.45 eq 5800 &lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any host 192.168.241.45 eq https &lt;/P&gt;&lt;P&gt;access-list 101 deny tcp object-group web_servers 172.16.1.0 255.255.255.0 eq www &lt;/P&gt;&lt;P&gt;access-list 101 permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl permit ip any 192.168.254.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_20 permit ip any 192.168.254.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 192.168.241.45 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 172.16.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool VPNClientsIPPool 192.168.254.1-192.168.254.254&lt;/P&gt;&lt;P&gt;pdm location 172.16.1.1 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 192.168.241.45 3389 172.16.1.1 3389 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 192.168.241.45 www 172.16.1.1 www netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.241.254 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3 &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10 &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 172.16.1.1 l1verp00l timeout 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3 &lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10 &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.241.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;http 172.16.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;crypto map outside_map client authentication TACACS+ &lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;isakmp nat-traversal 20&lt;/P&gt;&lt;P&gt;isakmp policy 20 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 20 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 20 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 20 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 20 lifetime 86400&lt;/P&gt;&lt;P&gt;vpngroup TestLab address-pool VPNClientsIPPool&lt;/P&gt;&lt;P&gt;vpngroup TestLab dns-server 127.0.0.1&lt;/P&gt;&lt;P&gt;vpngroup TestLab wins-server 127.0.0.1&lt;/P&gt;&lt;P&gt;vpngroup TestLab default-domain testlan.local&lt;/P&gt;&lt;P&gt;vpngroup TestLab idle-time 1800&lt;/P&gt;&lt;P&gt;vpngroup TestLab password ********&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2008 09:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-users-access-to-websites/m-p/1060202#M915890</guid>
      <dc:creator>a.ajiboye</dc:creator>
      <dc:date>2008-07-29T09:43:13Z</dc:date>
    </item>
  </channel>
</rss>

