Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Blocking Ports

Status
Not open for further replies.

simba327

MIS
Dec 4, 2002
17
0
0
US
Hi,

I have a PIX 515 with v. 6.1 software. I would like to restrict my users from connecting to the internet on ports 5190-5193 (which I'm told is what AOL uses). They are bypassing the URL filtering on the PIX (WebSense) by connecting to AOL and browsing through that.
 
just use access-lists and access-groups ...

eg: when you want to block access from inside to outside over port 5190 --> access-list inside deny tcp a a eq 5190
access-group inside in interface inside

or when you want to block the ports from 5190 to 5193

access-l inside deny tcp any any range 5190 5193

access-group inside in in in

Best regards
 
dmccabe - be aware that AOL IM reverts to port 80 if the ones you mentioned are not available. Plus the program can be run through a web browser entirely.

There are several discussions elsewhere on this subject. The most successful I have read of block entire networks owned by AOL using access-lists.

Good luck and let us know if you find success.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top