How to block certain website

Discussion in 'Cisco' started by Anver, Aug 4, 2007.

  1. Anver

    Anver Guest

    I am new to this, I would like to know

    how to block certain website through pix506 - is that possible?
    and time scheduled browsing.

    kindly advise

    Anver, Aug 4, 2007
  2. You can get commercial products, Websense or N2H2, which the
    PIX will work with to do filtering. These are expensive -- unless
    you are a company that needs this kind of facility, in which case
    they are a cost of doing business that could end up saving a lot of

    The filtering capabilities built directly into the PIX 506 are limited
    to IP addresses and ports, not site names. Thus if the users use
    a proxy service, even a trivial non-encrypting one, then the PIX 506
    would not be able to detect that. And if the web site to be blocked
    happens to share IP addresses with other sites, the PIX 506
    cannot look to see which name was requested so as to allow the
    "good" sites through but not the bad sites.

    The highest software version officially supported on the PIX 506
    is 6.3(5), which does not support timed ACLs. If you open up
    the PIX 506 and increase the memory in it, then you can get
    PIX 7.0, 7.1, or 7.2 to load into it and run, and those support
    timed ACLs. PIX 7.x is not officially supported in the PIX 506...
    and you would need a support contract to have access to PIX 7.x.
    Walter Roberson, Aug 4, 2007
