
1-10
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 1 Getting Started
Protecting Your Network from Attack
ActiveX Blocking
ActiveX controls, formerly known as OLE or OCX controls, are components that can be inserted into a
web page or other application. The PIX
Firewall ActiveX blocking feature blocks HTML <object>
commands and comments them out of the HTML web page. As a technology, ActiveX creates many
potential problems for the network clients including causing workstations to fail, introducing network
security problems, being used to attack servers, or being used to host attacks against servers.
Java Filtering
The Java Filtering feature lets you prevent Java applets from being downloaded by a system on a
protected network. Java applets are executable programs that may be prohibited by some security
policies because they can enable certain methods of attacking a protected network.
URL Filtering
You can use access control lists to prevent outbound access to specific websites, but configuring and
managing web usage this way is not very practical because of the size and dynamic nature of the Internet.
The recommended solution is to use the PIX
Firewall in conjunction with a separate server running one
of the following Internet filtering products:
• Websense Enterprise web filtering application (supported by PIX Firewall Version 5.3 or higher)
• Filtering by N2H2 for IFP-enabled devices (supported by PIX Firewall Version 6.2 or higher)
Compared to using access control lists, this reduces the administrative task and improves filtering
effectiveness. Also, because URL filtering is handled on a separate platform, the performance of the
PIX
Firewall is much less affected.
The PIX Firewall checks outgoing URL requests with the policy defined on the URL filtering server.
PIX
Firewall either permits or denies the connection, based on the response from the filtering server.
For further information, refer to either of the following websites:
http://www.websense.com
http://www.n2h2.com
Note PIX Firewall Version 6.3 or higher supports filtering of HTTPS and FTP sites when using the Websense
filtering server. PIX
Firewall Version 6.2 or higher supports filtering of long URLs, such as those
generated by search engines.
Configurable Proxy Pinging
The Configurable Proxy Pinging feature lets you control ICMP access to PIX Firewall interfaces. This
feature shields PIX
Firewall interfaces from detection by users on an external network.
Note We recommend that you grant permission for ICMP unreachable message type 3. Denying ICMP
unreachable messages disables ICMP Path MTU discovery, which can halt IPSec and PPTP traffic.
Comentários a estes Manuais