cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
432
Views
0
Helpful
1
Replies

Pix Filter Active-X

gerard.oconnor
Level 1
Level 1

Hi,

Our internet facing firewall is a Pix 525. For the past few years, we have had active-x filtering enabled, however recently due to business requirements we have had to disable it as there are 3rd party business sites that need to be accessed and they are using active-x to present the content.

From reading the command line reference guide, I see that if we were using Alias the filter would not check the content of this connection, however we are not using this at the moment.

My question is,

Is there a way to enable the filtering of active-x, while allowing active-x for only a selected number of sites ?

Thanks,

Gerard.

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

What you're after is an "except" option in the "filter activex" command, which unfortunately doesn't exist (although it does for most other filtering commands).

I would suggest you contact your Account Manager and have them put in an enhancement request for this. I wouldn't think it would be too hard to implement, seeing as it's in most other options already, but if no-one ever asks for it it'll probably never appear.

FYI, here's the "filter" command refernce:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/df.htm#wp1131454

Review Cisco Networking for a $25 gift card