Can Cisco ASA firewalls restrict Internet access to branch offices?
1445 pts.
0
Q:
Can Cisco ASA firewalls restrict Internet access to branch offices?
I have a PPP network between our three office locations. In the master location I have a DSL line connected to my Layer 2 (L2) switch via a Cisco ASA 5505 Firewall. My server (ADC/DHCP/Proxy) is connected to the L2 switch. My branch office locations obtain IP through this server. I am using a Squid Windows version for my proxy, and I'm not able to restrict the Internet connection to branch offices using Squid. How can I restrict branch office users from using the Internet connection?
ASKED: Feb 11 2009  6:11 PM GMT
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
0
205 pts.
0
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • AddThis Social Bookmark Button
Does your gateway / Firewall allow internet traffic from any IP or only through the PROXY Server ? If its open for all the IP's than users can bypass the proxy server and freely browse the internet. The best way to restrict the users is by restricting them to change any TCP / IP & Browser settings. Since you are using an AD this can easily be achieved through a Group Policy.

======================

I addition to the above you can control which IP's and protocols have connectivity to the internet via the ASA. Maybe set it up so that only you proxy has access to browse the Internet.

www.ketchumits.com
Last Answered: Mar 1 2009  11:11 PM GMT by Hoover87   205 pts.
Latest Contributors: Puneet   90 pts.
0
0
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

IT Knowledge Exchange Community Update for 02/17/09 - ITKE Community Blog   0 pts.  |   Feb 17 2009  3:51PM GMT

[...] Can Cisco ASA firewalls restrict Internet access to branch offices? [...]

 
0