Casio ISA550WBUN3K9 manual Blocking Outbound Traffic by Schedule and IP Address Range

Models: ISA550WBUN3K9

1 479
Download 479 pages 49.64 Kb
Page 280
Image 280

Firewall

6

 

Firewall and NAT Rule Configuration Examples

 

 

 

 

 

Services

CU-SEEME

 

 

Source Address

OutsideNetwork

 

 

Destination Address

InternalIP

 

 

Match Action

Permit

 

 

 

 

Blocking Outbound Traffic by Schedule and IP Address

Range

Use Case: Block all weekend Internet usage if the request originates from a specified range of IP addresses.

Solution: Create an address object with the range 10.1.1.1 to 10.1.1.100 called “TempNetwork” and a schedule called “Weekend” to define the time period when the firewall rule is in effect. Then create a firewall rule as follows:

From Zone

LAN

 

 

To Zone

WAN

 

 

Services

HTTP

 

 

Source Address

TempNetwork

 

 

Destination Address

Any

 

 

Schedule

Weekend

 

 

Match Action

Deny

 

 

Blocking Outbound Traffic to an Offsite Mail Server

Use Case: Block access to the SMTP service to prevent a user from sending email through an offsite mail server.

Solution: Create a host address object with the IP address 10.64.173.20 called “OffsiteMail” and then create a firewall rule as follows:

Cisco ISA500 Series Integrated Security Appliances Administration Guide

280

Page 280
Image 280
Casio ISA550WBUN3K9 manual Blocking Outbound Traffic by Schedule and IP Address Range