How can I block the outbound to a subnet?

I want to block all traffic to a subnet. Say, 12.34.56.x 255.255.255.0

What is a more simple/better way to do this?

Thank you

Jay

You can't block out on an interface with a pix, you can with IOS. on a pix, you must block traffic on a different interface. usually, this is done inside interface

access-list deny ip inside all 12.34.56.0 255.255.255.0

inside ip access list allow a whole

group-access to the Interior in the interface inside

allows you to block this traffic from entering the inside of the interface, and therefore the will does not have to go through the pix to the outside world

Tags: Cisco Security

Similar Questions

  • How can I block the users access to microsoft office?

    How can I block the users access to microsoft office?

    You must set "" permission to run on each of the Microsoft Office programs (word.exe, excel.exe, powerpnt.exe, etc.) such that the group 'Administrators' and the SYSTEM is allowed to run.  To do this, you do a right click on the .exe file, select 'Properties', then click on the 'Security' tab and change security as you wish.

    If you do not have a 'Security' tab, then it is because you have XP Home Edition, or if you have XP Pro with active Simple file sharing.  For XP Home, you must boot mode safe (repeatedly tap F8 at startup key) and login as an administrator to access this tab.  For XP Pro, follow the instructions in the following article:

    "How to disable the file sharing simple and how to set permissions on a shared folder in Windows XP"
      <>http://support.Microsoft.com/kb/307874 >

    HTH,
    JW

  • The manager wants to block the file history. How can I block the storage of files

    The manager wants to block the file history. How can I block the storage of files

    Hi Jaeyoung,

    Please see the following article on network end Points for creative cloud.

    https://helpx.Adobe.com/content/dam/help/attachments/Creative_Cloud_for_enterprise_Service _Endpoints.pdf? wcmmode = disabled

    It has information about what how can you block applications and different services.

    I hope this helps.

    Kind regards

    Sumit Singh

  • How can I block the SMTP for all users but mail server

    I can't understand (1) how can I refuse port 25 for all users on the network and allow for Exchange server SMTP, also I have MS Exchange, which manages the web and smtp and in my setup below you can see that there static mapping to publick ip with http/smtp only, then (2) how can we separate the traffic entering a publc IP will outside servers inside ex : (MSexchange public ip address is x.x.x.207-> http = 172.16.2.13, 172.16.2.14 = smtp)

    Thank you

    ___________________________________________________

    6.3 (1) version PIX

    interface ethernet0 car

    Auto interface ethernet1

    ethernet0 nameif outside security0

    nameif ethernet1 inside the security100

    names of

    name 172.16.4.10 pdc

    name 172.168.4.11 llc

    name 172.16.4.11 ftp

    object-group service E-mail tcp

    port-object eq www

    EQ smtp port object

    object-group service tcp - udp terminal

    3389 3389 port-object range

    object-group service mw tcp - udp

    Beach of port-object 367 367

    radmin tcp service object-group

    RemoteAdmin description

    4899 4899 object-port Beach

    object-group service mw1 tcp

    Beach of port-object 367 367

    access-list 101 tcp refuse any any eq smtp

    access-list 101 permit tcp any host object-group x.x.x.251 terminal

    access-list 101 permit tcp any host x.x.x.214 object-group radmin

    access-list 101 permit tcp any email host x.x.x.207 object-group

    access-list 101 permit tcp any host x.x.x.212 object-group mw1

    access-list 101 permit tcp any host x.x.x.211 eq ftp

    sheep ip access-list allow any 192.168.101.0 255.255.255.240

    IP address outside x.x.x.194 255.255.255.192

    IP address inside 172.16.2.1 255.255.0.0

    IP verify reverse path to the outside interface

    IP verify reverse path inside interface

    alarm action IP verification of information

    IP audit attack alarm drop action

    IP local pool mypool 192.168.101.1 - 192.168.101.20

    don't allow no history of pdm

    ARP timeout 14400

    Global interface 10 (external)

    NAT (inside) 0 access-list sheep

    NAT (inside) 10 0.0.0.0 0.0.0.0 0 0

    static (inside, outside) x.x.x.212 172.16.4.12 netmask 255.255.255.255 0 0

    static (inside, outside) x.x.x.251 172.16.4.51 netmask 255.255.255.255 0 0

    public static x.x.x.214 (Interior, exterior) pdc netmask 255.255.255.255 0 0

    public static x.x.x.211 (Interior, exterior) ftp netmask 255.255.255.255 0 0

    "REM # 172.16.2.13's Exchange with Outlook Web servers #

    static (inside, outside) x.x.x.207 172.16.2.13 netmask 255.255.255.255 0 0

    Access-group 101 in external interface

    Route outside 0.0.0.0 0.0.0.0 x.x.x.193 1

    enable floodguard

    Sysopt connection permit-pptp

    VPDN PPTP-VPDN-group accept dialin pptp

    VPDN group PPTP-VPDN-GROUP ppp authentication pap

    VPDN group PPTP-VPDN-GROUP ppp authentication chap

    VPDN group PPTP-VPDN-GROUP ppp mschap authentication

    VPDN group PPTP-VPDN-GROUP ppp encryption mppe 40

    VPDN group VPDN GROUP-PPTP client configuration address local mypool

    VPDN group VPDN GROUP-PPTP client configuration dns 172.16.2.6 172.16.4.6

    client PPTP-VPDN-GROUP VPDN group configuration wins nymc_pdc

    VPDN group VPDN GROUP-PPTP pptp echo 60

    VPDN group VPDN GROUP-PPTP client for local authentication

    VPDN username * password *.

    VPDN allow outside

    This is your problem:

    Access-group 101 in external interface

    You link this access list to your external interface. This means that the rules are applied to incoming traffic IN your network. The implicit IP any any rule is because you have not bound to an access list on your inside interface.

    To prevent users from going out, you will need this:

    access list permit tcp host exchange_IP OUTPUT no matter what eq smtp

    access list tcp OUTPUT deny any any eq smtp

    Access-group interface inside OUT

    See how this access list is linked to the inside interface... it will affect traffic leaving your network. Note: Once you apply this inside allow any interface it will remove the implicit.

  • How can I block the annoying social media tabs that open web pages on the left side. they totally block what I'm trying to read. I have more ad block

    I have ad block more with the help of masking extension element. Yet these annoying social media tabs always opens on the left side of many pages. What makes the small available playback area. I don't want that on my screen, any body know how
    I appreciate any help
    Thank you kindly
    Bry

    Many web pages are those * % # $((^ % # choses.)) There are two things
    You can try. (1) use AdBlock to block the image elements.
    2) go to the web page. After the page loads, mouse to the address bar
    and on the LEFT , click the icon. A window to display information of site should
    developed. Select more information. Now select support. Go through the menu
    and select block on anything with Facebook (and others) as his address.

    I searched for an add-on that will do it, but have not seen a.

  • How can I block the words? So if they appear in the Web site the Web site is blocked.

    My son is able to search for Web sites that have a "mature" content  Searching for words like 'Gay' 'mature'... among others.  How to block websites from him who is there?

    Hi KelliMarchant,

    Words cannot be blocked in parental control but the sites where your child will be redirected to can be blocked. To prevent your child to see some Web sites, see the Windows Live Family Safety Web site and choose a level of filtering that are appropriate for your child. To do this, please see the solution below article.

    How to prevent my child to see some Web sites or chatting online?

    After a change of Windows Live Family Safety settings, it's a good idea to update the family safety filter to ensure that it uses the updated settings.

    Thank you!

  • How can I block the popup menus that say things like back, reload, bookmark this page, etc. ?

    is not outside the pop - ups but internal to firefox to 'help' with navigation. Sometimes they appear when scrolling, and then when I click elsewhere on the page, a new menu will appear here. So frustrating! How can I stop this from happening?

    On Mac, optionally open the context menu if you press the left button of the mouse over a longer period.

    See:

  • How can I block the alert that appears when you try to access the GPS coordinates?

    I develop an application that has access to the GPS coordinates and when I try to access appear a message that says "a JavaScript asked the physical location of your device. You want to offer this to the script? Can I block this alert?

    If you use the HTML5 geolocation API (lots of examples on a google search) instead of blackberry.location.latitude etc., you will be asked only the first time.

  • How can I block the contstant interruption of no value add? I tried to block everything. Not happened with older Firefox.

    I am reminded constantly upgraded to the new version of Firefox. I did and since that time, all that I go on a link in my email, in a store, or shopping, I am bombarded with the Constsurf and other ads. I tried to block everything I could think of, nothing helps. It didn't happen with older versions.

    It could be the work of one of your modules, or even add / bad-ware.
    Look through your list of modules and make sure you know what each of them is
    and so. In addition, to check the programs that are on your computer
    Windows > start > Control Panel > uninstall programs.
    (Mac: open the "Applications" folder)
    Go through the list and a web search to check that you have not
    know what they are.

    The problems of Firefox caused by malicious software {web link}

  • How can I block the IP 63.209.69.107 in Windows 7

    When I search with google or bing and click on one of their links in the result, I redirected page http://63.209.69.107/search/web/ with completely independent research elements.

    We get so I copy the URL and passed into the address bar to go

    Thanks to all who responded, none of the sugestions worked, however, I went to the web site of Norton and downloaded Norton Power Ereaser (NPE.exe), it took 5 to 8 minutes, fixed all

  • Recent update killed my tab bookmark at the top of the screen, how can I cancel the recent change?

    I have three computers that run Mozilla, it is constantly on, it's the only one who still has the bookmark at the top left of the screen tab, others have lost my favorites and have no tabs at the top of the screen. How can I block the upgrade on one and cancel the upgrade on the other two? I have some bookmarks that I use all the months that took forever to find...

    Are you talking about the orange Firefox button being gone in the top left corner of Firefox?

    If so, press the Alt key to display the Menu bar, which has a Favorites menu item, then click on bookmarks.

  • How can I block pp that I do not know to send me emails

    I'm tired of getting emails from pp, that I don't know that I mark as spam but always seem to find in my Inbox how can I block the please and thank you

    Hey PatriciaBarringer,

    This thread has been created in the Internet Explorer forum. the moderation of Microsoft team has moved this thread to the windows - networking forum and put online.

  • How can I activate the pop-up Blocker

    How can I activate the blocker pop up on Firefox?

    drummershob said

    addons.Mozilla.org > Add-ons for Firefox > Extensions

    The Firefox Extensions section of AMO are for Office Max OSX, Firefox for Windows and Linux. Firefox Android extensions are to allplayer

    There is no section for the OS "Firefox".

  • How can I change the B key of "block images?

    Right-click on the image and then B will block the images. I want to change this key B or turn it off. Is it possible to do this? I still want to be able to block, but with the mouse only or with a different key of B.

    Also how can I check the forum? View, post not necessarily. Do I need an account special previledge to do?

    You can remove items from menu with the Menu Editor extension.

    https://addons.Mozilla.org/en-us/Firefox/addon/menu-editor/

  • How can I activate the pop-up blocked message?

    How can I activate the pop-up blocked message? When the message came I clicked on do not show this message again. I want this message to show when Firefox blocks a menu embedded, so I can allow the pop up if I want to.

    You can see a pop-up block icon in the right corner of the status bar if you have chosen to hide the information bar at the top.

    You can click on this icon of pop - up block on the status bar and remove the check mark [] «do not show an information message when pop-ups are blocked»

Maybe you are looking for

  • iMac Bootcamp slow disk? Upgrade SSD?

    Hello I have an iMac that I bought in January 2014. The configuration is: NVIDIA GeForce GT 750M 1 GB GDDR5 3.1 GHz Quad - core Intel Core i7, Turbo Boost up to 3.9 GHz 8 GB 1600 MHz DDR3 SDRAM - 2 x 4 GB 1 TB 5400 RPM Serial ATA hard drive Now, I ru

  • Is there a way convert several files in sequence at a time?

    I am looking for a way to convert files in sequence from 2012 to 2010 in decline. You are looking to do more than one at a time and I'd like to be able to convert a whole folder down.

  • VPIM Setup error - windows.exe

    I download vipm - windows.exe from here: https://lumen.ni.com/nicif/us/evaltlktdigbus/content.xhtml When I double-click vipm - windows.exe under Windows XP Pro, I get the following error, see jpg below: is there a work around?  I want to see the I2C

  • megabytes and kilobytes

    who is the bigger MB or KB

  • Windows 7 and the multipage tiff document

    I use Windows 7 and Internet Explorer 9 Professional version of Office 2010. Franklin County recorder records all the deeds of several pages as .tif files and I'm unable to read, save or print them. The recorder recomments a third party but tif Viewe