Couple things here I would like your opinion on. We have a pix 515 ver6.1(1)
1. I want to retrict all outbound (traffic with the exception of web traffic and maybe audio streaming lol
from our LAN. To keep us from infecting others with viruses. I have no idea on how to do this.
2. Our network keeps getting hit by viruses. I realize that the pix closes all the ports on the outside interface by default but I do not know how these virus's keep getting inside. Granted a lot of them travel via email but we had a few that were hit with the msblast virus. We do have nortons installed on all pc's and servers and it stops it but I want to stop the worms, virus's etc. at the border. I'm not for sure if I should build a proxy/firewall pc or try and lock everything down with a the pix. I guess one of my questions is if teh pix has all ports closed on the outside int then how dows virus's still get in if not through email?
Your opinion on both these matters would be greatly appreciated.
Thanx
1. I want to retrict all outbound (traffic with the exception of web traffic and maybe audio streaming lol

2. Our network keeps getting hit by viruses. I realize that the pix closes all the ports on the outside interface by default but I do not know how these virus's keep getting inside. Granted a lot of them travel via email but we had a few that were hit with the msblast virus. We do have nortons installed on all pc's and servers and it stops it but I want to stop the worms, virus's etc. at the border. I'm not for sure if I should build a proxy/firewall pc or try and lock everything down with a the pix. I guess one of my questions is if teh pix has all ports closed on the outside int then how dows virus's still get in if not through email?
Your opinion on both these matters would be greatly appreciated.
Thanx