Access Control List Example

pixfirewall(config)# access-list 101 deny tcp any any eq www pixfirewall(config)# access-group 101 in interface inside

• Packet filtering rules (access control lists) restrict outbound access

• Filters on source or destination IP address, protocol, and port or application

Deny HTTP from network

In the figure above, the PIX Firewall denies HTTP connections from an internal network, but lets all other traffic through.

