cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
460
Views
5
Helpful
3
Replies

blocking http for user

anthony.dyne
Level 1
Level 1

Hello

We need to block one user from browsing internet and allow all others. For now I only have ACL on the outside interface.

The user is behind the Firewall ( i.e LAN )

Current setup allows all users to browse internet.

appreicate some help

thanks

Anthony

1 Accepted Solution

Accepted Solutions

Right on the money - that will do it.  Just make sure the user will ALWAYS be 172.20.20.1 - if he changes, he will bypass the ACL.

HTH>

View solution in original post

3 Replies 3

andrew.prince
Level 10
Level 10

Create another ACL for the "Inside" to deny the specific host and permit all else.

Hello Andrew

Are these entries correct

access-list INSIDE extended deny tcp host 172.20.20.1 any eq http

access-list INSIDE extended permit ip any any

access-group INSIDE in interface inside

thanks

Anthony

Right on the money - that will do it.  Just make sure the user will ALWAYS be 172.20.20.1 - if he changes, he will bypass the ACL.

HTH>

Review Cisco Networking products for a $25 gift card