<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FireSIGHT URL Not Blocking on First View in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-url-not-blocking-on-first-view/m-p/2588076#M1028209</link>
    <description>&lt;P&gt;This is a new installation of an ASA5545 with FireSIght licensed for URL filtering&lt;/P&gt;&lt;P&gt;We wrote a&amp;nbsp;rule for "block" not "block with reset" for URLs containing "Adult and Pornography" and applied it. It did work but only after the second view of the page. After the second view it did&amp;nbsp;block the URL and the "Access Denied" screen was displayed. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Was this a user configuration issue or a FireSight issue???&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 12:36:47 GMT</pubDate>
    <dc:creator>TOM FRANCHINA</dc:creator>
    <dc:date>2019-03-12T12:36:47Z</dc:date>
    <item>
      <title>FireSIGHT URL Not Blocking on First View</title>
      <link>https://community.cisco.com/t5/network-security/firesight-url-not-blocking-on-first-view/m-p/2588076#M1028209</link>
      <description>&lt;P&gt;This is a new installation of an ASA5545 with FireSIght licensed for URL filtering&lt;/P&gt;&lt;P&gt;We wrote a&amp;nbsp;rule for "block" not "block with reset" for URLs containing "Adult and Pornography" and applied it. It did work but only after the second view of the page. After the second view it did&amp;nbsp;block the URL and the "Access Denied" screen was displayed. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Was this a user configuration issue or a FireSight issue???&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-url-not-blocking-on-first-view/m-p/2588076#M1028209</guid>
      <dc:creator>TOM FRANCHINA</dc:creator>
      <dc:date>2019-03-12T12:36:47Z</dc:date>
    </item>
    <item>
      <title>Was there already an</title>
      <link>https://community.cisco.com/t5/network-security/firesight-url-not-blocking-on-first-view/m-p/2588077#M1028210</link>
      <description>&lt;P&gt;Was there already an established tcp connection from the client you're testing from? If so, that would be used and not trigger the URL filter.&lt;/P&gt;&lt;P&gt;Test by first doing "clear conn" on the ASA&amp;nbsp;and then hit the page with a fresh first view.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jan 2015 14:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-url-not-blocking-on-first-view/m-p/2588077#M1028210</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-01-18T14:31:25Z</dc:date>
    </item>
    <item>
      <title>Hi Tom,not sure if this is</title>
      <link>https://community.cisco.com/t5/network-security/firesight-url-not-blocking-on-first-view/m-p/2588078#M1028211</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;not sure if this is related (I'm new with FireSIGHT myself) but...&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Before you can perform user control using a group criterion, the system must detect activity from at least one user in that group. This initial connection is &lt;B class="cBold"&gt;not&lt;/B&gt; handled by the access control rule it matches, but instead by the next rule it matches, or the access control policy default action."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa-firepower-module-user-guide-v541/AC-Rules-User.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa-firepower-module-user-guide-v541/AC-Rules-User.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2015 12:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-url-not-blocking-on-first-view/m-p/2588078#M1028211</guid>
      <dc:creator>Rodrigo Belo</dc:creator>
      <dc:date>2015-03-31T12:31:15Z</dc:date>
    </item>
  </channel>
</rss>

