<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOS Zone Based Firewall URLvisited logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-zone-based-firewall-urlvisited-logging/m-p/5053848#M1110543</link>
    <description>&lt;P&gt;Hello, for reasons of compliance we are required to syslog URL visited.&lt;/P&gt;&lt;P&gt;With the config below (not full) I am able to see the IP visited, and this only for http.&lt;/P&gt;&lt;P&gt;Is there a way to syslog the http and https URLs ?&lt;/P&gt;&lt;P&gt;parameter-map type urlf-glob PERMITTEDSITES&lt;BR /&gt;pattern *&lt;/P&gt;&lt;P&gt;class-map type urlfilter match-any BLOCKEDSITES&lt;BR /&gt;match server-domain urlf-glob BLOCKEDSITES&lt;BR /&gt;class-map type inspect match-any HTTP&lt;/P&gt;&lt;P&gt;class-map type inspect match-any INSIDE-TO-OUTSIDE-CLASS&lt;BR /&gt;match access-group name INSIDE-TO-OUTSIDE&lt;/P&gt;&lt;P&gt;policy-map type inspect urlfilter CONTENT-FILTERING&lt;BR /&gt;class type urlfilter BLOCKEDSITES&lt;BR /&gt;log&lt;BR /&gt;allow&lt;BR /&gt;class type urlfilter PERMITTEDSITES&lt;BR /&gt;allow&lt;BR /&gt;log&lt;BR /&gt;policy-map type inspect INSIDE-TO-OUTSIDE-POLICY&lt;BR /&gt;class type inspect HTTP&lt;BR /&gt;inspect&lt;BR /&gt;service-policy urlfilter CONTENT-FILTERING&lt;BR /&gt;class type inspect HTTPS&lt;BR /&gt;inspect&lt;BR /&gt;class type inspect DNS&lt;BR /&gt;inspect&lt;BR /&gt;class class-default&lt;BR /&gt;pass&lt;/P&gt;&lt;P&gt;Which produces logs of the type:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;190&amp;gt;2719: *Mar 31 13:35:11.239: %URLF-6-SITE_ALLOWED: (target:class)-(IN-TO-OUT:HTTP):Client 10.XXX.XXX.237:63774 accessed server 146.75.118.172:80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 31 Mar 2024 14:42:21 GMT</pubDate>
    <dc:creator>Tony_S</dc:creator>
    <dc:date>2024-03-31T14:42:21Z</dc:date>
    <item>
      <title>IOS Zone Based Firewall URLvisited logging</title>
      <link>https://community.cisco.com/t5/network-security/ios-zone-based-firewall-urlvisited-logging/m-p/5053848#M1110543</link>
      <description>&lt;P&gt;Hello, for reasons of compliance we are required to syslog URL visited.&lt;/P&gt;&lt;P&gt;With the config below (not full) I am able to see the IP visited, and this only for http.&lt;/P&gt;&lt;P&gt;Is there a way to syslog the http and https URLs ?&lt;/P&gt;&lt;P&gt;parameter-map type urlf-glob PERMITTEDSITES&lt;BR /&gt;pattern *&lt;/P&gt;&lt;P&gt;class-map type urlfilter match-any BLOCKEDSITES&lt;BR /&gt;match server-domain urlf-glob BLOCKEDSITES&lt;BR /&gt;class-map type inspect match-any HTTP&lt;/P&gt;&lt;P&gt;class-map type inspect match-any INSIDE-TO-OUTSIDE-CLASS&lt;BR /&gt;match access-group name INSIDE-TO-OUTSIDE&lt;/P&gt;&lt;P&gt;policy-map type inspect urlfilter CONTENT-FILTERING&lt;BR /&gt;class type urlfilter BLOCKEDSITES&lt;BR /&gt;log&lt;BR /&gt;allow&lt;BR /&gt;class type urlfilter PERMITTEDSITES&lt;BR /&gt;allow&lt;BR /&gt;log&lt;BR /&gt;policy-map type inspect INSIDE-TO-OUTSIDE-POLICY&lt;BR /&gt;class type inspect HTTP&lt;BR /&gt;inspect&lt;BR /&gt;service-policy urlfilter CONTENT-FILTERING&lt;BR /&gt;class type inspect HTTPS&lt;BR /&gt;inspect&lt;BR /&gt;class type inspect DNS&lt;BR /&gt;inspect&lt;BR /&gt;class class-default&lt;BR /&gt;pass&lt;/P&gt;&lt;P&gt;Which produces logs of the type:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;190&amp;gt;2719: *Mar 31 13:35:11.239: %URLF-6-SITE_ALLOWED: (target:class)-(IN-TO-OUT:HTTP):Client 10.XXX.XXX.237:63774 accessed server 146.75.118.172:80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2024 14:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-zone-based-firewall-urlvisited-logging/m-p/5053848#M1110543</guid>
      <dc:creator>Tony_S</dc:creator>
      <dc:date>2024-03-31T14:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: IOS Zone Based Firewall URLvisited logging</title>
      <link>https://community.cisco.com/t5/network-security/ios-zone-based-firewall-urlvisited-logging/m-p/5054481#M1110558</link>
      <description>&lt;P&gt;There is command ""alert"" check it&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 17:57:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-zone-based-firewall-urlvisited-logging/m-p/5054481#M1110558</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-01T17:57:21Z</dc:date>
    </item>
  </channel>
</rss>

