Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 6.3(5) outside address blocking

Status
Not open for further replies.

tonloc69

IS-IT--Management
Aug 1, 2008
3
US
I have a PIX at ver 6.3(5) and I would like to block access to several websites. I have the IP addresses of the websites but I am unsure how to do the access-list command to block the site.

We currently have a command in the conf.

name 66.151.149.78 Online_radio_001
outbound 1 deny Online_radio_001 255.255.255.255 0 ip


Would this block access to the specified ip address? If not...how would we do it? I was thinking about the access-list command but I don't think it works in the 6.3 version.

Regards.
 
To block an internet address on a Pix 6.3 do the following:

sh access-group

Look for the access-list on the outside interface


object-group Blocked_internet
network-object host <ip1>
network-object host <ip2>
exit

access-list <acl name from above> deny ip object-group Blocked_internet any

wr mem


IT Security news and information
In plain English
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top