Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Port blocking with PIX and Websense 1

Status
Not open for further replies.

netadmin65

Technical User
Feb 14, 2003
61
US

I'm trying to block ports using the "Protocol Sets"
policies in Websense, adding the necessary ports in
the "Protocols" section.

First of all, yes, I know I can use access lists in
the PIX to do the same thing, but it is much easier
to do it in WebSense.

The problem is, that the PIX will only block what
it sees in the "filter" commands, which as of now, are
only HTTP, HTTPS, and FTP.

Is there a way that the PIX (using Websense) can
block the ports listed under the sub-headings in
the "Protocols" section in WebSense?
 
I may have already answered my question, but I do
need verification on this:

I think I'll be able to do port blocking from
a machine set up as a WebSense "Network Agent".

Would someone please confirm this?

Thanks
 
We use Websense with the Network agent to block ports and protocols on the Pix, what you need to do is configure the Network Agent to be able to see all the traffic on your internal Pix interace. We do this on a managed switch using monitor ports, switches by default wont do this for you.

You then configure your protocol rules in Websense to block / allow as you desire, then test using standard applications such and Messenger and music downloads.

The network agent when you install it, comes with a test to see if it can see your network traffic. Hope this all helps.

Regards

Terry
 
Hi lockdown.

I gave you a star. This appears to work fine.
The star is for telling me about the network test.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top