You need to have a third party applications such as
Websense or N2H2 to do this. Without 3rd party applications, this can NOT be done on the Pix firewall,
unless, you do a "nslookup" and block by IPs on the pix.
But that is a very stupid way to do it on Cisco Pix.
The people who designed the Pix is not very smart people,
IMHO. That is not to say that I am smart either but
why they didn't figure this in the first place is beyond
me.
That being said, this can be done rather easily with
Checkpoint Firewalls. There is a feature called "domain"
object that you can use to block websites. Blocking web
sites via "domain" is a poor man approach. If you want
something fancy, you can also use 3 party applications
such as N2H2 or Websense to do the same thing as Cisco Pix.
HTH
Wirelesspeap
CCSA-NG/CCSE-NG
Cisco CCIE Security