Solved

Dan you use DNS entries in Pix Access Control Lists?

Posted on 2007-11-15
1
264 Views
Last Modified: 2010-04-09
Folks, hopefully this is an easy one.  
We have a Pix that we are trying to limit outside web browsing to a few web sites.  I can set up the ACL with no issues and it works with no complaints.  Then the web site address changed and no access to the web site.

Is there a way to list just the DNS name of the web site in the ACL and have the Pix box do the DNS resolution on it's own?  It would save a tremdous amount of  time instead of listing the IP addresses of the web sites (Yahoo Maps happens to be one of the sites we are constantly changing).

0
Comment
Question by:Sean_E_Smith
1 Comment
 
LVL 36

Accepted Solution

by:
grblades earned 125 total points
ID: 20289092
No you cannot do that.

The PIX does support products like Websense which can be used to filter on a URL basis.

The way I do it is to force everyone to use a central proxy server and then only allow the proxy to access websites. You can then do all the URL filter on the proxy server.
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

There are many useful and sometimes not well documented or forgotten IOS or ASA/PIX commands. See IPE article here , there was also one on PacketU and on Cisco Tips & Tricks. Below are my favorites. I give also a few most often used for Cisco IPS an…
Cisco Pix/ASA hairpinning The term, hairpinning, comes from the fact that the traffic comes from one source into a router or similar device, makes a U-turn, and goes back the same way it came. Visualize this and you will see something that looks …
This video discusses moving either the default database or any database to a new volume.
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now