<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Vaibhav, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873695#M1030247</link>
    <description>&lt;P&gt;Hi Vaibhav,&lt;/P&gt;
&lt;P&gt;You don't need to create new access control policy. Edit the default policy and then inside that policy, create rules.&lt;/P&gt;
&lt;P&gt;only 1 access control policy will be applied to the device at one time.&lt;/P&gt;
&lt;P&gt;Inside the access control policy, you can create rules based on category or custom URL.&lt;/P&gt;
&lt;P&gt;Please check this article.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/117956-technote-sourcefire-00.html&lt;/P&gt;
&lt;P&gt;Though this is for firesight but the rule creation process is same in ASDM as well.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
    <pubDate>Sun, 03 Jul 2016 06:13:23 GMT</pubDate>
    <dc:creator>yogdhanu</dc:creator>
    <dc:date>2016-07-03T06:13:23Z</dc:date>
    <item>
      <title>Cisco Firepower configuration through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873694#M1030246</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was trying to configure Cisco Firepower URL filtering through ASDM.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;However I am trying to create access policy through ASDM &amp;nbsp;but i am getting confused about the next steps. Please find the attached screenshot.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Where to go next?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873694#M1030246</guid>
      <dc:creator>vaibhav58</dc:creator>
      <dc:date>2019-03-12T13:03:27Z</dc:date>
    </item>
    <item>
      <title>Hi Vaibhav,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873695#M1030247</link>
      <description>&lt;P&gt;Hi Vaibhav,&lt;/P&gt;
&lt;P&gt;You don't need to create new access control policy. Edit the default policy and then inside that policy, create rules.&lt;/P&gt;
&lt;P&gt;only 1 access control policy will be applied to the device at one time.&lt;/P&gt;
&lt;P&gt;Inside the access control policy, you can create rules based on category or custom URL.&lt;/P&gt;
&lt;P&gt;Please check this article.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/117956-technote-sourcefire-00.html&lt;/P&gt;
&lt;P&gt;Though this is for firesight but the rule creation process is same in ASDM as well.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2016 06:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873695#M1030247</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-07-03T06:13:23Z</dc:date>
    </item>
    <item>
      <title>Thanks Yogesh.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873696#M1030248</link>
      <description>&lt;P&gt;Thanks Yogesh.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was able to create a access policy. I created a standard rule to block social network websites but the access still goes through, i cannot see any traffic on my firepower logging monitor.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I do have the commands on my asa to redirect traffic to firepower:&lt;/P&gt;
&lt;P&gt;EFC-FW# sh run | in sfr&lt;BR /&gt;access-list sfr_redirect extended permit ip any any&lt;BR /&gt;class-map sfr&lt;BR /&gt; match access-list sfr_redirect&lt;BR /&gt; class sfr&lt;BR /&gt; sfr fail-open&lt;BR /&gt;EFC-FW#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please let me know what i am missing!! Awaiting your reply&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2016 14:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873696#M1030248</guid>
      <dc:creator>vaibhav58</dc:creator>
      <dc:date>2016-07-03T14:20:53Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873697#M1030249</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am getting this message in my logs:&lt;/P&gt;
&lt;P&gt;SFR requested ASA to bypass further packet redirection and process TCP flow from inside&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any idea on this.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2016 16:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873697#M1030249</guid>
      <dc:creator>vaibhav58</dc:creator>
      <dc:date>2016-07-03T16:07:49Z</dc:date>
    </item>
    <item>
      <title>Hi Vaibhav,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873698#M1030250</link>
      <description>&lt;P&gt;Hi Vaibhav,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You might want to check this video regarding url filtering and see if the settings match :&lt;/P&gt;
&lt;P&gt;https://www.youtube.com/watch?v=nXIBDQqekPY&lt;/P&gt;
&lt;P&gt;Looks like in your case , the correct policy is not getting hit.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just check the video for a bit of troubleshooting and let us know if it helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate and mark helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 05:03:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873698#M1030250</guid>
      <dc:creator>ankojha</dc:creator>
      <dc:date>2016-07-04T05:03:12Z</dc:date>
    </item>
    <item>
      <title>HI Ankita,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873699#M1030251</link>
      <description>&lt;P&gt;HI Ankita,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This video of yours was the first i watched to get into this further. Thanks for it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am now able to block URL objects but not via category. Looks like i have an issue for my SFR module not able to connect to internet. For some reason , i was not able to ssh into my sfr module after getting into ASA, although it was working earlier.&lt;/P&gt;
&lt;P&gt;I did found that HTTPS port need to be openend bidirectionally for updates to work. I have it opened to any to outside but none for inbound.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What IP address does the SFR module takes to connect to the internet ? Is it management IP? What IP address i use to open a rule for inbound HTTP/HTTPS for this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 08:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873699#M1030251</guid>
      <dc:creator>vaibhav58</dc:creator>
      <dc:date>2016-07-04T08:08:34Z</dc:date>
    </item>
    <item>
      <title>Hello Team ,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873700#M1030252</link>
      <description>&lt;P&gt;Hello Team ,&lt;/P&gt;
&lt;P&gt;For all the url filtering updates to be work, you have to open the following ports in the Firewall:-&lt;/P&gt;
&lt;P&gt;Uses port 443 (bidirectional)&lt;BR /&gt;Uses port 80 (inbound)&lt;/P&gt;
&lt;P&gt;Refer the following link to verify if you met all the requirements for the URL filtering to work.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Communication-Ports.html&lt;/P&gt;
&lt;P&gt;Rate if the post helps you&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 08:15:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873700#M1030252</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-07-04T08:15:04Z</dc:date>
    </item>
    <item>
      <title>Hi Jetsy, thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873701#M1030253</link>
      <description>&lt;P&gt;Hi Jetsy, thanks for the reply. I am using ASDM and thus having trouble for URL updates.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please advise what &amp;nbsp;access list i need to make for inbound https.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What interface does the firepower module uses for its outbound connection to internet?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 08:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873701#M1030253</guid>
      <dc:creator>vaibhav58</dc:creator>
      <dc:date>2016-07-04T08:49:36Z</dc:date>
    </item>
    <item>
      <title>Hi Vaibhav,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873702#M1030254</link>
      <description>&lt;P&gt;Hi Vaibhav,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The sfr module uses its management ip for going out to internet so make sure&lt;/P&gt;
&lt;P&gt;the default which you are assigning to sfr module is able to reach internet.&lt;/P&gt;
&lt;P&gt;You can allow all access to and fro for the management ip of sfr module.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;rate if it helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 06:41:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873702#M1030254</guid>
      <dc:creator>ankojha</dc:creator>
      <dc:date>2016-07-05T06:41:45Z</dc:date>
    </item>
    <item>
      <title>Hi Ankita,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873703#M1030255</link>
      <description>&lt;P&gt;Hi Ankita,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for the info, i will try this and let you know the updates.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is this not a security issue to open access to the module from outside.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My management IP of the module is 192.168.10.2.Since i need bidirectional, i would require a static NAT bidirectional.&lt;/P&gt;
&lt;P&gt;One more thing , when i click on URL category update and check logs on ASDM i do not see any traffic from 192.168.10.2. This is the reason I wanted to check which IP address firepower uses.&lt;/P&gt;
&lt;P&gt;Also , are you aware of any list of IP Address to allow from outside. I am reluctant to open any .I saw this &amp;nbsp;from another document:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Domain&lt;/STRONG&gt;: &lt;FONT face="courier new,courier"&gt;support.sourcefire.com&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;URL&lt;/STRONG&gt;: &lt;FONT face="courier new,courier"&gt;https://support.sourcefire.com&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Port&lt;/STRONG&gt;: &lt;FONT face="courier new,courier"&gt;443/tcp&lt;/FONT&gt; (bidirectional)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;IP Address&lt;/STRONG&gt;: &lt;FONT face="courier new,courier"&gt;50.19.123.95&lt;FONT face="helvetica"&gt;,&lt;/FONT&gt; 50.16.210.129&lt;BR /&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Additional IP Addresses that are also used by the &lt;FONT face="courier new,courier"&gt;support.sourcefire.com&lt;/FONT&gt; (in round robin method) are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.210.248&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.211.1&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.212.60&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.212.170&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.212.241&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.213.96&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.213.209&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.214.25&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;54.221.214.81&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;thanks in advance.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;regards&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Vaibhav&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 11:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873703#M1030255</guid>
      <dc:creator>vaibhav58</dc:creator>
      <dc:date>2016-07-05T11:30:39Z</dc:date>
    </item>
    <item>
      <title>HI Ankita,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873704#M1030256</link>
      <description>&lt;P&gt;HI Ankita,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The issue is now resolved. There was a DNS issue. DNS server was configured and the process has to be restarted.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No inbound connection was needed.&lt;/P&gt;
&lt;P&gt;Thanks for alll the help!!&lt;/P&gt;
&lt;P&gt;Really appreciated.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 21:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/2873704#M1030256</guid>
      <dc:creator>vaibhav58</dc:creator>
      <dc:date>2016-07-05T21:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/3899459#M1030257</link>
      <description>&lt;P&gt;Have you heard back anything on this?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 17:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/3899459#M1030257</guid>
      <dc:creator>pro_engineering</dc:creator>
      <dc:date>2019-07-29T17:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/3899691#M1030258</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/132156"&gt;@pro_engineering&lt;/a&gt;&amp;nbsp;this is a 3 year old thread. Please open a new discussion if you have current questions.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 03:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-configuration-through-asdm/m-p/3899691#M1030258</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-30T03:33:31Z</dc:date>
    </item>
  </channel>
</rss>

