cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1383
Views
0
Helpful
3
Replies

Pix 525 Block internal computers

m-norman
Level 1
Level 1

Hello....very new to using the Pix 525. I would like to block a range of private ip address within my private network blocking them from going to the interenet. I work for a school and have virtual networks setup with private ip addresses for each building. I have labs in some of these buildings and want to be able to block internet access to these labs and then turn them back on at a later date. How would I be able to do this. Thanks for your help!

3 Replies 3

pdentico
Level 1
Level 1

You can limit use with the "nat" command or with access-lists. Either one will work, how you would do it will depend on how your IP addressing is setup internally.

Okay....I have an outside and inside interface on the pix would. I create an access list for the inside interface to deny a particular host to the outside interface? Again I apologize if I sound uneducated on this question. Thanks...

using the access list would be a little more difficult. If these ips you want to block are on a different subnet than your other users then just dont include them in any static or nat (#) commands. or you can do nat 0 if they are a private ip that way they are not natted and cannot get out to the internet

Review Cisco Networking for a $25 gift card