Blocking Outbound Traffic By Schedule And Ip Address Range - Cisco ISA550 Administration Manual

Isa500 series integrated security appliances
Hide thumbs Also See for ISA550:
Table of Contents

Advertisement

Firewall
Firewall and NAT Rule Configuration Examples
Cisco ISA500 Series Integrated Security Appliances Administration Guide
Services
Source Address
Destination Address
Match Action
Blocking Outbound Traffic by Schedule and IP Address
Range
Use Case: Block all weekend Internet usage if the request originates from a
specified range of IP addresses.
Solution: Create an address object with the range 10. 1 . 1 . 1 to 10. 1 . 1 . 1 00 called
"TempNetwork" and a schedule called "Weekend" to define the time period when
the firewall rule is in effect. Then create a firewall rule as follows:
From Zone
To Zone
Services
Source Address
Destination Address
Schedule
Match Action
Blocking Outbound Traffic to an Offsite Mail Server
Use Case: Block access to the SMTP service to prevent a user from sending email
through an offsite mail server.
Solution: Create a host address object with the IP address 10.64. 1 73.20 called
"OffsiteMail" and then create a firewall rule as follows:
CU-SEEME
OutsideNetwork
InternalIP
Permit
LAN
WAN
HTTP
TempNetwork
Any
Weekend
Deny
6
232

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Isa550wIsa570Isa570w

Table of Contents