Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX Block Internal user from accessing rane of ports 1

Status
Not open for further replies.

DaveGreeko

IS-IT--Management
Oct 20, 2006
11
0
0
US
Hello everyone,
My Cisco guy left the company and I urgently need the proper Access-list command to block one host (10.10.10.42) in our LAN from accessing the internet except a list of external IPs belong to our bank with port 443.
Any help is greatly appreciated.

Our PIX is 506E with version is 6.3(5)
Thank you again
 
Access-list outbound permit tcp host 10.10.10.42 host [DESTINATION_IP] eq 443 ****repeat per allowed IP
Access-list outbound deny ip host 10.10.10.42 any
Access-list outbound permit ip any any

access-group outbound in interface inside

If you have external DNS resolution add this right after the allowed IPs but before the deny statement...
Access-list outbound permit udp host 10.10.10.42 any eq dns

Hope this helps


Brent
Systems Engineer / Consultant
CCNP, CCSP
 
Thank you so much Brent. It's the way I wanted and it's working perfect [2thumbsup]. Thanks again and have a productive weekend
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top