<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Whiltelisting on ASA without FirePOWER license in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712446#M14441</link>
    <description>&lt;P&gt;You can build one as example shown below document.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/asa-url-filtering-without-a-websense-or-n2h2-smartfilter-server/ta-p/3116352" target="_blank"&gt;https://community.cisco.com/t5/security-documents/asa-url-filtering-without-a-websense-or-n2h2-smartfilter-server/ta-p/3116352&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/115998-asa-http-product-configuration-example-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/115998-asa-http-product-configuration-example-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/100535-asa-8x-regex-config.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/100535-asa-8x-regex-config.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Sep 2018 20:40:20 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2018-09-24T20:40:20Z</dc:date>
    <item>
      <title>URL Whiltelisting on ASA without FirePOWER license</title>
      <link>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712110#M14436</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;We want to deny all outbound web access except to a group of about 10 whitelist URL domains on an ASA 5525-X with FirePOWER services. Is it possible to do this on the ASA without an add-on FirePower license? Will this have a significant performance impact?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712110#M14436</guid>
      <dc:creator>PETER NEGUS</dc:creator>
      <dc:date>2020-02-21T16:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: URL Whiltelisting on ASA without FirePOWER license</title>
      <link>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712148#M14438</link>
      <description>&lt;P&gt;It is possible to create an object within the ASA using a FQDN. To do this the ASA has to be able to resolve names.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dns domain-lookup inside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;name-server x.x.x.x&lt;BR /&gt;&amp;nbsp;domain-name company.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example of a FQDN object&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network site.example.com&lt;BR /&gt;&amp;nbsp;fqdn site.example.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You then put this into an ACL. i.e. access-list inside-in extended permit tcp object inside-networks object site.example.com eq www &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note issues will occur if a site utilises global load balancers, where your inside clients resolve site.example.com as xyz but the ASA gets the IP zyx. Also, you can't do wildcards i.e. *.microsoft.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ultimately, if it's really basic you can do it. Otherwise you need something designed for a web gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Joel&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 14:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712148#M14438</guid>
      <dc:creator>Joel</dc:creator>
      <dc:date>2018-09-24T14:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: URL Whiltelisting on ASA without FirePOWER license</title>
      <link>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712158#M14440</link>
      <description>Thank you very much for your suggestion. Unfortunately it doesn't work in our case because we have multiple target hosts within a domain, which need to be expressed as a wildcard - for example *.anynet.network.com . As the FQDN is based on a DNS lookup, wildcards don't work.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sorry for not making my initial query clearer&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Peter&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Sep 2018 14:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712158#M14440</guid>
      <dc:creator>PETER NEGUS</dc:creator>
      <dc:date>2018-09-24T14:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: URL Whiltelisting on ASA without FirePOWER license</title>
      <link>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712446#M14441</link>
      <description>&lt;P&gt;You can build one as example shown below document.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/asa-url-filtering-without-a-websense-or-n2h2-smartfilter-server/ta-p/3116352" target="_blank"&gt;https://community.cisco.com/t5/security-documents/asa-url-filtering-without-a-websense-or-n2h2-smartfilter-server/ta-p/3116352&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/115998-asa-http-product-configuration-example-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/115998-asa-http-product-configuration-example-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/100535-asa-8x-regex-config.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/100535-asa-8x-regex-config.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 20:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712446#M14441</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-09-24T20:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: URL Whiltelisting on ASA without FirePOWER license</title>
      <link>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712745#M14443</link>
      <description>Hi Balaji&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you very much for your suggestions. Do you know if this will require a FirePOWER license, and if so, which one?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Sep 2018 11:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712745#M14443</guid>
      <dc:creator>PETER NEGUS</dc:creator>
      <dc:date>2018-09-25T11:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: URL Whiltelisting on ASA without FirePOWER license</title>
      <link>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712831#M14446</link>
      <description>&lt;P&gt;The MPF/regex-based approach doesn't require the Firepower service module at all. No special ASA license is required - just the base software.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I almost never see it in use in live networks though as it never caught on since it's so burdensome to configure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A much more sustainable solution is to use Firepower with URL Filtering or, better yet, Cisco Umbrella.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 13:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-whiltelisting-on-asa-without-firepower-license/m-p/3712831#M14446</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-25T13:33:24Z</dc:date>
    </item>
  </channel>
</rss>

