<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dear All, Just an update, i in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674894#M191686</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just an update, i can successfully blocked the Https sites like yahoo, twitter, youtube with the following access list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.x.x.x object-group Blocked-URL eq https&lt;/P&gt;&lt;P&gt;but facebook and instagram, un-able to block it. Even the IP is correct for the websites getting through DNS. I can block the ping for facebook and even all websites but not the https.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Waiting if anyone can help me&lt;/P&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.1.1.1 object-group Blocked-URL eq https log - See more at: https://supportforums.cisco.com/discussion/12505326/url-blocking-facebookcom-cisco-asa-using-object-acl#sthash.FvY5t4V1.dpuf&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.1.1.1 object-group Blocked-URL eq https log - See more at: https://supportforums.cisco.com/discussion/12505326/url-blocking-facebookcom-cisco-asa-using-object-acl#sthash.FvY5t4V1.dpuf&lt;/DIV&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.1.1.1 object-group Blocked-URL eq https log - See more at: https://supportforums.cisco.com/discussion/12505326/url-blocking-facebookcom-cisco-asa-using-object-acl#sthash.FvY5t4V1.dpuf&lt;/DIV&gt;</description>
    <pubDate>Tue, 12 May 2015 21:57:47 GMT</pubDate>
    <dc:creator>Ali Haider</dc:creator>
    <dc:date>2015-05-12T21:57:47Z</dc:date>
    <item>
      <title>URl Blocking (Facebook.com) on Cisco ASA by Using Object ACL</title>
      <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674893#M191685</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I am trying to block the URL like facebook.com on the ASA, i used the mentioned of object ACL by using FQDN name as object. It is resolving the DNS name perfectly so i can have all the IPs of facebook.co,.&lt;/P&gt;&lt;P&gt;&amp;nbsp;i configure the following ACL which can only block the layer 3 communication based on the IP, and when i ping from the PC to "ping facebook.com" it is blocked on the firewall and i can see the hit count on the ACL which is fair enough .&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;access-list INSIDE_IN line 2 extended deny ip host 10.1.1.9 object-group Blocked-URL log&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is i configured the same below ACL just to block the https, some of the websites it is blocking but facebook.com is still working. Some time it blocked but mostly it would not.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.1.1.1 object-group Blocked-URL eq https log &lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me to sort out what exactly problem is, i am using 8.4(2) version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is any other way to do it let me know&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:55:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674893#M191685</guid>
      <dc:creator>Ali Haider</dc:creator>
      <dc:date>2019-03-12T05:55:15Z</dc:date>
    </item>
    <item>
      <title>Dear All, Just an update, i</title>
      <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674894#M191686</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just an update, i can successfully blocked the Https sites like yahoo, twitter, youtube with the following access list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.x.x.x object-group Blocked-URL eq https&lt;/P&gt;&lt;P&gt;but facebook and instagram, un-able to block it. Even the IP is correct for the websites getting through DNS. I can block the ping for facebook and even all websites but not the https.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Waiting if anyone can help me&lt;/P&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.1.1.1 object-group Blocked-URL eq https log - See more at: https://supportforums.cisco.com/discussion/12505326/url-blocking-facebookcom-cisco-asa-using-object-acl#sthash.FvY5t4V1.dpuf&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.1.1.1 object-group Blocked-URL eq https log - See more at: https://supportforums.cisco.com/discussion/12505326/url-blocking-facebookcom-cisco-asa-using-object-acl#sthash.FvY5t4V1.dpuf&lt;/DIV&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;access-list INSIDE_IN line 3 extended deny tcp host 10.1.1.1 object-group Blocked-URL eq https log - See more at: https://supportforums.cisco.com/discussion/12505326/url-blocking-facebookcom-cisco-asa-using-object-acl#sthash.FvY5t4V1.dpuf&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 May 2015 21:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674894#M191686</guid>
      <dc:creator>Ali Haider</dc:creator>
      <dc:date>2015-05-12T21:57:47Z</dc:date>
    </item>
    <item>
      <title>Hi Ali, Based on your configs</title>
      <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674895#M191687</link>
      <description>&lt;P&gt;Hi Ali,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on your configs, that should work already.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you try to erase the cache of your browser then try it again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 15:39:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674895#M191687</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2015-05-13T15:39:39Z</dc:date>
    </item>
    <item>
      <title>Dear Nikko, Thank you very</title>
      <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674896#M191688</link>
      <description>&lt;P&gt;Dear Nikko,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your valuable input, i was skipping this point while testing it. It worked but instagram.com still its not blocked even after clear the cache. For the rest of the URls i can see the ACL hitcount is increasing and also blocking the websites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this leads me to another finding which is, if i access the URL directly from the browser it blocked, means open a browser and type https://facebook.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i go first on the google.com and search facebook.com and then click on the link then it again worked, it means when i initiate the session directly from my PC to the blocked URL it blocked but when i initiate it to any other web and then try to open blocked URL (https only) it open.&lt;/P&gt;&lt;P&gt;But this behaviour is not true for the http website, http website is blocked by any mean to access it either directly or through the search engine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE: for the above finding i can conclude that directly https:facebook.com is blocked because it is just blocking based on the IP resolved by DNS but when i access the same web through &lt;A href="https://google.com" target="_blank"&gt;https://google.com&lt;/A&gt; it bypass the ACL because it is going as encrypted in https?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE: I am&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 20:58:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674896#M191688</guid>
      <dc:creator>Ali Haider</dc:creator>
      <dc:date>2015-05-13T20:58:11Z</dc:date>
    </item>
    <item>
      <title>Hi Ali, Good day! Thanks for</title>
      <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674897#M191689</link>
      <description>&lt;P&gt;Hi Ali,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good day!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for sharing your findings and that's a bit strange behavior of the ASA. I think you need to try using the CX function if you have because it can also have URL filtering capabilities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 04:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674897#M191689</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2015-05-14T04:22:05Z</dc:date>
    </item>
    <item>
      <title>Hi, Unfortunately we dont</title>
      <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674898#M191690</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately we dont have CX, but i dont want to inspect the payload. just trying to get L4 blocked. Only the difference between the traditional ACL and the ACL i am using it with FQDN.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 15:59:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674898#M191690</guid>
      <dc:creator>Ali Haider</dc:creator>
      <dc:date>2015-05-14T15:59:28Z</dc:date>
    </item>
    <item>
      <title>Hi, Just to addition to my</title>
      <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674899#M191691</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to addition to my above email can you please give me any link for CX module supported in ASA5580?&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 16:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674899#M191691</guid>
      <dc:creator>Ali Haider</dc:creator>
      <dc:date>2015-05-14T16:39:48Z</dc:date>
    </item>
    <item>
      <title>Hi Ali, you can try to check</title>
      <link>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674900#M191692</link>
      <description>&lt;P&gt;Hi Ali, you can try to check the link below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 10:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-blocking-facebook-com-on-cisco-asa-by-using-object-acl/m-p/2674900#M191692</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2015-05-18T10:10:43Z</dc:date>
    </item>
  </channel>
</rss>

