Re: [fw-wiz] Cisco ASA 5510 and proxy server detection



On Wed, 2006-02-08 at 14:03 -0500, nick leachman wrote:
Aaron, I'm not fluent on the 5510 per se; but if you are
authenticating to an external AAA server such as a RADIUS server you
might be able to set up downloadable ACLs and tie them to the users
who are to be denied Internet access.


Absolutely. Same idea, just applied to a subset of users. Requires a
AAA back-end instead of just a couple of ACLs on the ASA.

The ACLs would permit traffic only to and from your internal network;
so if they tried to head into the wild they'd get denied - period.


From my understanding of the original post, that's the behavior he
wanted for ALL hosts on the inside:

On Tue, 2006-02-07 at 06:05 -0800, John Madden wrote:
Hi,

Is there a way to NOT permit users from the inside to
connect to a proxy server on the outside and bypassing
the Web filtering software ?




________________________________________________________________________

@@ron Smith <smitha@xxxxxxxx>
Network Operations
Brigham Young University Idaho



_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Asynchronous Processing Web age
    ... Off hand I'd lean towards option #1, as it tends to tie up fewer ... resources on the server. ... how long the 3 asynch processes need to complete, so #1 may not be THE ... >2) Synchronously call a monitor function on the server that poll the status ...
    (microsoft.public.dotnet.framework.aspnet)
  • something completely different
    ... Server is: Apache/1.3.33 ... I Googled this and came up with what appears to be a tie in with Apple ... Computers Inc. and a domain name of store.apple.com. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Which OS?
    ... Assuming I increase the amount of RAM, ... I'd install 2000 on it along with all patches and tie down a desktop for ... it's slow to boot it's surprisingly okay as a file server for my LAN:) ... 2003 server is a solid continuation of the 2k line - pretty low memory ...
    (uk.comp.homebuilt)
  • SBS2003 for 3 locations
    ... would like to tie together with a server for file sharing, internet access, ...
    (microsoft.public.windows.server.sbs)
  • Re: Burn, baby, burn
    ... the machine can't multitask while burning the CD. ... 3000 (PII 333) is better used as a server. ... So the machine to tie up is ...
    (comp.sys.ibm.ps2.hardware)