Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Simple question: How i block an external IP?

hi.. i am new here and dont understand much about firewalls, but i need to block an internet IP that attacking my network, how i can do it?

i try some configs but nothing work

where i can read some basic manual to configure mi firewall?

Here is my info

Cisco PIX Firewall Version 6.3(3)

Cisco PIX Device Manager Version 3.0(1)

2 REPLIES
Cisco Employee

Re: Simple question: How i block an external IP?

hi,

find out the IP address first, then make an access-list and apply it on outside interface

access-list 100 deny ip host any

access-group 100 in interface outside

if you already have an ACL applied on outside interface, then you have to add the deny first

thanks

Nadeem

Re: Simple question: How i block an external IP?

If you often have to block such hosts it might be good to use object groups. Like that you can easy add and remove hosts in the object group instead add and remove them in the access-list. This helps also to keep short your access-list.

Blacklist on outside interface example:

object-group network Blacklist

network-object host x.x.x.2

network-object host b.c.y.x

exit

access-list outside deny ip object-group Blacklist any

access-group outside in interface outside

examples:

Controlling Network Access and Use:

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008017278e.html

Configuration Examples and TechNotes:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_configuration_examples_list.html

Using and Configuring PIX Object Groups

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800d641d.shtml

sincererly

Patrick

230
Views
0
Helpful
2
Replies