Re: Internet access



I don't have pix anymore on the hand, but you may use some basic feature to achieve your goal.

I think you may add basic cisco authentification on the rule that allow http/https outside. If so, you may use local account on the pix, or use radius (IAS on the Windows server) to let them authenticate with their windows account.
As i don't have a pix on hand, and i was used to bigger one, it may not be possible.



--
Cordialement,
Mathieu CHATEAU
English blog: http://lordoftheping.blogspot.com
French blog: http://www.lotp.fr


"reptil" <c.reptil@xxxxxxxxx> wrote in message news:m33ql3hd8od2t4c9avb5voi2ig57ebnnks@xxxxxxxxxx
515E
Ok, :))), that is problem. If I restrict IE or firefox there is possibillity for download on all other ports.
This 2 people use a same computers like other 10 people in this room because we work in 3 shifts and this 2 people work just in 1st shift.
Now I have restricted IP's on PIX, so I'm finding new solution, but the best solution is as I think it is with proxy.

Thnx for advices



What is your pix model ? 501 ?

You may tweak IE with bad proxy through GPO (and firefox through a custom
ADM), but that won't stop bad guys (or people with more knowledge).

Does these 2 people have their own personal computers ? If so, you can
easily restrict by ip addresses.

.



Relevant Pages

  • Re: Redirecting all Outgoing http traffic to an internal Web server
    ... that any traffic or traffic from specific vlans on port 80 or port ... 8080 (depending on whats your proxy port) be forwarded to the proxy ip ... L3 and pix. ... a mask for the destination to be matched. ...
    (comp.dcom.sys.cisco)
  • Re: Redirecting all Outgoing http traffic to an internal Web server
    ... proxy address) to an internal web server from the Pix 525 firewall. ... that won't work on a PIX or ASA. ... a mask for the destination to be matched. ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] pix/proxy issue
    ... You have two proxy servers in your PIX DMZ for internal users. ... internet via virtual ip addresses assigned to each of the boxes. ...
    (Firewall-Wizards)
  • Internet traffic through VPN to
    ... The problem I am having is that HQ has a proxy that monitors Internet ... They can get to unauthorized and blocked websites. ... the PIX will not send packets back ...
    (comp.dcom.sys.cisco)
  • Re: Internet traffic through VPN to
    ... The problem I am having is that HQ has a proxy that monitors Internet ... the PIX will not send packets back ... If it allows only internal IP ranges, rest of the traffic from branch office will be sent to internet directly. ...
    (comp.dcom.sys.cisco)