cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
597
Views
0
Helpful
1
Replies

Blocking Certain Authenticated Users (Privileged) From The Internet

Is it possible to develop rules within a WSA to block authenticated privileged users from accessing the Internet?  A network engineer believes that the previous security team had this working in the past (over two years ago), but none of the team remain in the organization.

1 Accepted Solution

Accepted Solutions

Ana Peric
Cisco Employee
Cisco Employee

Hi Bernard,

The question here is: how do you define "Authenticated privileged users"?

In general, let us assume we are forcing authentication (thus you have Authentication-based Identification Policy).

If you create new AD group that will contain "all the authenticated users that you wish to block", you can easily make the access policy to:

- Use authentication identity

- Match your AD group of "blocked.users

- Access policy will in essence "Block all protocols" and show the EUN page

I hope this is what you had in mind, if not, please clarify what type of users you want to block, but in essence logic would be the same.

Cheers,
Ana

View solution in original post

1 Reply 1

Ana Peric
Cisco Employee
Cisco Employee

Hi Bernard,

The question here is: how do you define "Authenticated privileged users"?

In general, let us assume we are forcing authentication (thus you have Authentication-based Identification Policy).

If you create new AD group that will contain "all the authenticated users that you wish to block", you can easily make the access policy to:

- Use authentication identity

- Match your AD group of "blocked.users

- Access policy will in essence "Block all protocols" and show the EUN page

I hope this is what you had in mind, if not, please clarify what type of users you want to block, but in essence logic would be the same.

Cheers,
Ana

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: