• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 867
  • Last Modified:

blocking hotmail and yahoo.com in ASA 5510

ANY IDEAS HOW TO BLOCK HOTMAIL AND YAHOO through ASA5510  VER 8.0(4)
0
alimohammed72
Asked:
alimohammed72
  • 2
1 Solution
 
MikeKaneCommented:
In an ASA Firewall you can block any outbound request using an Access list.   THE ACL is read in sequential order, top to bottom, so as soon as there is a match the processing stops.  

Your list would need to look something like this:

Access-list inside_to_outside extended deny ip any <ip address subnet of hotmail>  <subnet mask of hotmail>
Access-list inside_to_outside extended deny ip any <ip address subnet of yahoo>  <subnet mask of yahoo>
Access-list inside_to_outside extended permit tcp any any eq 80
Access-list inside_to_outside extended permit tcp any any eq 443

access-group inside_to_outside in interface inside

This will block any ip request to the ip subnet of hotmail or yahoo yet allow any other port 80/443 request outbound.   There is an implicit deny at the end of any access list, so all other communication would be blocked.  


0
 
alimohammed72Author Commented:
how am I going to know the subnets for Hotmail and Yahoo
0
 
MikeKaneCommented:
Here are the hotmail ips
http://wiki.answers.com/Q/How_do_you_block_hotmail.com

Here are the yahoo ips
 66.163.0.0/16
 67.195.186.0/24
68.142.230.0/24
 69.147.112.0/24
 98.136.112.0/24
208.69.32.0/24
216.136.0.0/16



You know that anyone can still hit a public proxy then get to these sites....     Or setup a personal proxy at home and bypass this ip range.      The best way to block this would be setup a web filter like websense and block the webmail category along with the proxy/anonymizer category.  


0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now