User's Manual

Table Of Contents
Firewall
Firewall Access Rule Configuration Examples
Cisco ISA500 Series Integrated Security Appliance Administrator Guide 191
6
Blocking Outbound Traffic By Schedule and IP Address Range
User Case: Block all weekend Internet usage if the request originates from a
specified range of IP addresses.
Solution: Create a range address object with the range 10.1.1.1 to 10.1.1.100
called “TempNetwork” and a schedule called “Weekend” to define the time period
when the access rule is in effect, and then configure an access rule as follows.
Blocking Outbound Traffic to an Offsite Mail Server
User Case: If you want to block access to the SMTP service to prevent a user
from sending email through an offsite mail server.
Solution: Create a host address object with the IP address 10.64.173.20 called
“OffsiteMail”, and then configure an access rule as follows.
Source Address OutsideNetwork
Destination Address InternalIP
Match Action Permit
Parameter Value
From Zone LAN
To Zone WAN
Services HTTP
Source Address Te m p N e t w o r k
Destination Address Any
Schedule Weekend
Match Action Deny
Parameter Value
From Zone LAN
To Zone WAN
Parameter Value