Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Blocking Ports

Status
Not open for further replies.

simba327

MIS
Dec 4, 2002
17
US
Hi,

I have a PIX 515 with v. 6.1 software. I would like to restrict my users from connecting to the internet on ports 5190-5193 (which I'm told is what AOL uses). They are bypassing the URL filtering on the PIX (WebSense) by connecting to AOL and browsing through that.
 
just use access-lists and access-groups ...

eg: when you want to block access from inside to outside over port 5190 --> access-list inside deny tcp a a eq 5190
access-group inside in interface inside

or when you want to block the ports from 5190 to 5193

access-l inside deny tcp any any range 5190 5193

access-group inside in in in

Best regards
 
dmccabe - be aware that AOL IM reverts to port 80 if the ones you mentioned are not available. Plus the program can be run through a web browser entirely.

There are several discussions elsewhere on this subject. The most successful I have read of block entire networks owned by AOL using access-lists.

Good luck and let us know if you find success.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top