Cisco SA520-K9 Administration Guide - Page 116

Blocking Outbound Traffic By Schedule and IP Address Range, Solution, Action, Source Hosts

Page 116 highlights

Firewall Configuration Firewall Rule Configuration Examples 4 Parameter Action Source Hosts From To Send to Local Server (DNAT IP) Value ALLOW always Address Range 132.177.88.2 134.177.88.254 192.168.75.11 (internal IP address) Blocking Outbound Traffic By Schedule and IP Address Range Use Case: Block all weekend Internet usage if the request originates from a specified range of IP addresses. Solution: Set up a schedule called "Weekend" to define the time period when the rule is in effect. Configure an outbound rule that applies to traffic from marketing group, which has an IP address range of 10.1.1.1 to 10.1.1.100. Parameter From Zone To Zone Service Action Schedule Source Hosts From To Destination Hosts Value Secure (LAN) INSECURE (Dedicated WAN/Optional WAN) HTTP BLOCK by schedule Weekend Address Range 10.1.1.1 10.1.1.100 Any Cisco SA500 Series Security Appliances Administration Guide 116

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

Firewall Configuration
Firewall Rule Configuration Examples
Cisco SA500 Series Security Appliances Administration Guide
116
4
Blocking Outbound Traffic By Schedule and IP Address Range
Use Case:
Block all weekend Internet usage if the request originates from a
specified range of IP addresses.
Solution:
Set up a schedule called “Weekend” to define the time period when the
rule is in effect. Configure an outbound rule that applies to traffic from marketing
group, which has an IP address range of 10.1.1.1 to 10.1.1.100.
Action
ALLOW always
Source Hosts
Address Range
From
132.177.88.2
To
134.177.88.254
Send to Local Server
(DNAT IP)
192.168.75.11
(internal IP address)
Parameter
Value
From Zone
Secure (LAN)
To Zone
INSECURE (Dedicated WAN/Optional
WAN)
Service
HTTP
Action
BLOCK by schedule
Schedule
Weekend
Source Hosts
Address Range
From
10.1.1.1
To
10.1.1.100
Destination Hosts
Any
Parameter
Value