<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I'm having real issues with in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757005#M1026454</link>
    <description>&lt;P&gt;I'm having real issues with these modules. Even with a simple policy they don't seem to be reliable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've installed/migrated/upgraded the appliances and have no such issues, but every SFR module I've put in is becoming a&amp;nbsp;nightmare.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've found that the only time an interactive block page is presented is when a static URL is specified, if it involves a cloud lookup then it just doesn't load the page at all, as&amp;nbsp;if the reset is sent without the "interactive" part. Another issue our customer is experiencing is that when a category is set to block and reset, the initial page loads but when navigating further it then provides the block. As you can imagine some webpages show some explicit content on the&amp;nbsp;home page and this is unacceptable in my opinion.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also seeing lots of issues with ASDM managed modules in that lots of GUI glitches are happening when looking at the configuration or monitoring pages, but only on the firepower sections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is causing lots of frustration and needs sorting out.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2015 15:20:50 GMT</pubDate>
    <dc:creator>GarySLear</dc:creator>
    <dc:date>2015-10-08T15:20:50Z</dc:date>
    <item>
      <title>URL filtering - not blocking</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2756999#M1026448</link>
      <description>&lt;P&gt;I have URL filtering set up on FireSight and my ASA 5525-X. &amp;nbsp;I have noticed that it does not block unwanted pages.&lt;/P&gt;&lt;P&gt;It shows up in Defense Center&amp;nbsp;events as "interactive block with reset", but the page is actually never blocked. &amp;nbsp;&lt;/P&gt;&lt;P&gt;It appears to be trying to block the page? &amp;nbsp;When I visit a "blocked" site, the site takes a long time to load. &amp;nbsp;The cursor just spins and you think it is going to time out, then after 15 seconds the page&amp;nbsp;loads.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running version 5.4.1.1 on my DC and 5.4.0.3 on my ASA module.&lt;/P&gt;&lt;P&gt;I have configured a monitoring rule before the block rule as was suggested in the forums.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2756999#M1026448</guid>
      <dc:creator>Dave Phillips</dc:creator>
      <dc:date>2019-03-12T12:44:30Z</dc:date>
    </item>
    <item>
      <title>You have to create a rule</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757000#M1026449</link>
      <description>&lt;P&gt;You have to create a rule under the Access Control Policy, and apply the access control policy.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 23:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757000#M1026449</guid>
      <dc:creator>Ed Padilla Jr</dc:creator>
      <dc:date>2015-08-13T23:47:02Z</dc:date>
    </item>
    <item>
      <title>I do have a rule.  In the</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757001#M1026450</link>
      <description>&lt;P&gt;I do have a rule. &amp;nbsp;In the access control policy I have a rule set it to "interactively block with reset" for several categories (gambling, porn) as well as a custom object. &amp;nbsp;I also have a rule right above this one to "monitor" for the same categories. &amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like Firesight is trying to block the page as it logs the action correctly, but I never see the block page and like I mentioned it eventually loads.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 00:06:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757001#M1026450</guid>
      <dc:creator>Dave Phillips</dc:creator>
      <dc:date>2015-08-14T00:06:35Z</dc:date>
    </item>
    <item>
      <title>Because you have chosen the</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757002#M1026451</link>
      <description>&lt;P&gt;Because you have chosen the interactive block it allows the client to 'click through' or simply refresh their webpage and essentially ignore the blocking action. What is likely happening for you is that the browser is automatically refreshing and rebuilding the connection. If you look at your connection events you should see a block for the first connection attempt followed by an allowed on the refresh.&lt;/P&gt;&lt;P&gt;Now as to the&amp;nbsp;reason you aren't seeing the interactive block message there are a few possibilities.&lt;/P&gt;&lt;P align="LEFT"&gt;&lt;FONT face="Times-Roman" size="2"&gt;&lt;FONT face="Times-Roman" size="2"&gt;Note that in the following situations, the response page does &lt;/FONT&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT face="Times-Bold" size="2"&gt;&lt;FONT face="Times-Bold" size="2"&gt;not &lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT face="Times-Roman" size="2"&gt;&lt;FONT face="Times-Roman" size="2"&gt;appear and traffic is blocked without &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face="Times-Roman" size="2"&gt;&lt;FONT face="Times-Roman" size="2"&gt;interaction, even if the session matches an Interactive Block rule:&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P align="LEFT"&gt;&lt;FONT face="Univers-CondensedBold" size="1"&gt;&lt;FONT face="Univers-CondensedBold" size="1"&gt;&lt;B&gt;• &lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face="Times-Roman" size="2"&gt;&lt;FONT face="Times-Roman" size="2"&gt;if the session was or is encrypted; this includes sessions decrypted by the system&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P align="LEFT"&gt;&lt;FONT face="Univers-CondensedBold" size="1"&gt;&lt;FONT face="Univers-CondensedBold" size="1"&gt;&lt;B&gt;• &lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face="Times-Roman" size="2"&gt;&lt;FONT face="Times-Roman" size="2"&gt;after a connection has been established and allowed to flow for a few packets so the system can &lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face="Times-Roman" size="2"&gt;&lt;FONT face="Times-Roman" size="2"&gt;inspect it for requested URLs and application details&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P align="LEFT"&gt;&amp;nbsp;I have seen some funky behavior with the response pages as well on the ASA w/ Firepower so if anyone has some more insight there I'd love to see it.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 15:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757002#M1026451</guid>
      <dc:creator>rcmcdermott11</dc:creator>
      <dc:date>2015-08-14T15:55:38Z</dc:date>
    </item>
    <item>
      <title>I managed to get the URLs</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757003#M1026452</link>
      <description>&lt;P&gt;I managed to get the URLs blocked by changing the action to "block". &amp;nbsp;I still do not get a block page, the blocked URL just doesn't load.&lt;/P&gt;&lt;P&gt;I like the Firesight product so far, but I think the URL filtering has room for A LOT of improvement. &amp;nbsp;I was hoping to replace of my current expensive, bloated web filtering product, but I wont be able to with the current state of the software right now.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 16:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757003#M1026452</guid>
      <dc:creator>Dave Phillips</dc:creator>
      <dc:date>2015-08-14T16:49:51Z</dc:date>
    </item>
    <item>
      <title>Fairly familiar with the</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757004#M1026453</link>
      <description>&lt;P&gt;Fairly familiar with the product, but if you create a customize block page, would that work?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 16:56:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757004#M1026453</guid>
      <dc:creator>Ed Padilla Jr</dc:creator>
      <dc:date>2015-08-14T16:56:05Z</dc:date>
    </item>
    <item>
      <title>I'm having real issues with</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757005#M1026454</link>
      <description>&lt;P&gt;I'm having real issues with these modules. Even with a simple policy they don't seem to be reliable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've installed/migrated/upgraded the appliances and have no such issues, but every SFR module I've put in is becoming a&amp;nbsp;nightmare.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've found that the only time an interactive block page is presented is when a static URL is specified, if it involves a cloud lookup then it just doesn't load the page at all, as&amp;nbsp;if the reset is sent without the "interactive" part. Another issue our customer is experiencing is that when a category is set to block and reset, the initial page loads but when navigating further it then provides the block. As you can imagine some webpages show some explicit content on the&amp;nbsp;home page and this is unacceptable in my opinion.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also seeing lots of issues with ASDM managed modules in that lots of GUI glitches are happening when looking at the configuration or monitoring pages, but only on the firepower sections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is causing lots of frustration and needs sorting out.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 15:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-not-blocking/m-p/2757005#M1026454</guid>
      <dc:creator>GarySLear</dc:creator>
      <dc:date>2015-10-08T15:20:50Z</dc:date>
    </item>
  </channel>
</rss>

