cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1645
Views
0
Helpful
4
Replies

Block on ASA 5100

jerrybu01
Level 1
Level 1

Hi everyone,

I have a cisco asa 5510 version 8.3. My company has a internet policy company like that;

client use range IP 192.168.100.0/24

My boss wants to block a range IP from 192.168.100.20 to 192.168.100.200, but they can access skype, email and company website.

the rest of ip allow all.

i know how to block a website, but i don't know to config above. help me?

4 Replies 4

jocamare
Level 4
Level 4

The tricky part will be Skype, the rest is easy.

Skype uses dynamic ports and sometimes it encrypts the traffic, so there is no way [on the ASA] to match for this traffic and let it go through, not even deny it.

You can try an IPS solution since there are some signatures configured to detect that traffic, but i wouldn't recommended it as the ultimate solution.

Skype was designed to be sneaky and bypass firewalls and filters.

Besides, not all the traffic you want to block goes through the ASA, does it?

Yes,

with range IP 192.168.100.20/24 - 192.168.100.200/24--> i will block all traffic (not including email, a website compay..)

The rest of Ip address full traffic

If we are going to block everything but mail and access to an specific website, you can use acls for that.

It was already define we can't block Skype.

thanks jocamare!

Review Cisco Networking for a $25 gift card