Firewall
Firewall Access Rule Configuration Examples
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
191
6
Blocking Outbound Traffic By Schedule and IP Address Range
User Case:
Block all weekend Internet usage if the request originates from a
specified range of IP addresses.
Solution:
Create a range address object with the range 10.1.1.1 to 10.1.1.100
called “TempNetwork” and a schedule called “Weekend” to define the time period
when the access rule is in effect, and then configure an access rule as follows.
Blocking Outbound Traffic to an Offsite Mail Server
User Case:
If you want to block access to the SMTP service to prevent a user
from sending email through an offsite mail server.
Solution:
Create a host address object with the IP address 10.64.173.20 called
“OffsiteMail”, and then configure an access rule as follows.
Source Address
OutsideNetwork
Destination Address
InternalIP
Match Action
Permit
Parameter
Value
From Zone
LAN
To Zone
WAN
Services
HTTP
Source Address
TempNetwork
Destination Address
Any
Schedule
Weekend
Match Action
Deny
Parameter
Value
From Zone
LAN
To Zone
WAN
Parameter
Value