I am having a problem in my Pix FW to block a particular network to go to the internet. Here is the scenerio.
My FW has 3 interfaces: Outside(Sce 0), Inside (Sec100) and DMZ(Sce50). Whole inside block (let say 10.x.x.x) is being NATed (Here using DynamicNAT/PAT) to the Outside Interface while going towards Internet. NAT 0 is using between Inside and DMZ Servers to communicate. Here is the configuration.
global (Outside) 1 interface
nat (Inside) 1 access-list nat
access-list Nat_ACL extended permit ip 10.0.0.0 255.0.0.0 any log
Now what the problem is - I want to block a specific network 10.10.10.0/24 to go to the the Internet. I tried to change the Nat_ACL ACL here by denying the 10.10.10.0/24 to any and then allow/permit 10.x.x.x to any. But it didn't work.
Any suggestion or ideas or any other way how can I block this 10.10.10.0/24 to go to the Internet. Ur help would be highly appreciable.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...