Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco ACLs for Domain names

Status
Not open for further replies.

Tier2

Vendor
Apr 28, 2004
2
US
Has anyone used this method before on Cisco IOS Firewall ?
(example: A group of users that need to get to only a few web sites ) Using ACLs, what if the web site has multiple address resolution ? Or what if the domains IP changes ? Any thoughts !
 
If you want to check/restrict web surfing, you will be better off using filtering proxies (squidguard, dansguardian and such). Otherwise, you could easily spend half your life running after IP changes.
 
One easy way that I learned to use was through Proxy Policies. We have a policy set up for Non-Internet users to proxy to our Intranet host. It is not a real proxy, so every site they try to access comes up with our Intranet. But because there was 2 sites that were valid, you can add exclusions to the rule.

Works great!

Thanks,

Matt Wray

GFH

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top