Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Newbie Question

Reply
Thread Tools

Newbie Question

 
 
Mike
Guest
Posts: n/a
 
      12-24-2003
Hello,

I need to block traffic on my Pix 515, specifcally junk web traffic, which
is not TCP:80. I need to allow my users to surf, but want to eliminate
streaming web music, weather programs that constantly hit the Net, Kazaa,
spyware, etc, etc.... I know that some of these apps scan open ports and
use those, but is there an easy way to block everything except for the
basics (TCP 80, 25, 110, etc)? I have a Pix 515 with v6.3.

Thanks,
Mike




-----= Posted via Newsfeeds.Com, Uncensored Usenet News =-----
http://www.newsfeeds.com - The #1 Newsgroup Service in the World!
-----== Over 100,000 Newsgroups - 19 Different Servers! =-----
 
Reply With Quote
 
 
 
 
Andrey Tarasov
Guest
Posts: n/a
 
      12-24-2003
Hello, Mike!
You wrote on Wed, 24 Dec 2003 08:36:52 -0500:

M> I need to block traffic on my Pix 515, specifcally junk web
M> traffic, which is not TCP:80. I need to allow my users to
M> surf, but want to eliminate streaming web music, weather
M> programs that constantly hit the Net, Kazaa, spyware, etc,
M> etc.... I know that some of these apps scan open ports and use
M> those, but is there an easy way to block everything except for
M> the basics (TCP 80, 25, 110, etc)? I have a Pix 515 with v6.3.

You will need more than just a PIX to do what you are looking for. Cisco NBAR
and Packeteer PacketShaper come to my mind. First one is technology and run on
Cisco router, second one is a product. Idea behind is simple - application
recognition.

Trying to block everything except 80, 25, 110, etc. can potentially break some
legitimate traffic. On the other hand there is TCP over HTTP and TCP over DNS
available - so you really want to look into payload.

With best regards,
Andrey.

 
Reply With Quote
 
 
 
 
Guest
Posts: n/a
 
      12-26-2003

> M> I need to block traffic on my Pix 515, specifcally junk web
> M> traffic, which is not TCP:80. I need to allow my users to
> M> surf, but want to eliminate streaming web music, weather
> M> programs that constantly hit the Net, Kazaa, spyware, etc,
> M> etc.... I know that some of these apps scan open ports and use
> M> those, but is there an easy way to block everything except for
> M> the basics (TCP 80, 25, 110, etc)? I have a Pix 515 with v6.3.
>
> You will need more than just a PIX to do what you are looking for. Cisco

NBAR
> and Packeteer PacketShaper come to my mind. First one is technology and

run on
> Cisco router, second one is a product. Idea behind is simple - application
> recognition.
>
> Trying to block everything except 80, 25, 110, etc. can potentially break

some
> legitimate traffic. On the other hand there is TCP over HTTP and TCP over

DNS
> available - so you really want to look into payload.
>
> With best regards,
> Andrey.


I agree with Andrey that you would need something other then the PIX to do
properly, content inspection is what you need and this is not a feature of
the firewall. It also has it's own problems blocking legitimate traffic.

But, you can use a simple ACL to block all outbound except the ports you
mentioned, you will just have to put in exceptions for legitimate traffic
when the user complains. And they will.


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VONAGE Newbie w/newbie question New_kid@nowhere.new VOIP 0 08-11-2007 01:40 PM
another newbie question from another newbie.... Lee UK VOIP 4 05-17-2005 04:10 PM
newbie: cisco vlan newbie question No Spam Cisco 3 06-07-2004 10:02 AM
dumb newbie question (or newbie dumb question) Jerry C. Perl Misc 8 11-23-2003 04:11 AM
Newbie! I'm a newbie! What's wrong with this program? Id0x Python 4 07-20-2003 11:40 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57