<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA andalso would like to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668351#M195207</link>
    <description>&lt;P&gt;ASA&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;also would like to know whether general router has this function and how to do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;actually i mean not only web site, for example, in window , share drive, net drive, in linux, you can get file with ftp , or get software, or other kind of methods.&lt;/P&gt;&lt;P&gt;i just afraid hackers can get word file, movie file, or photo&amp;nbsp;if they succeed to pass firewall&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2015 18:17:04 GMT</pubDate>
    <dc:creator>Maivoko</dc:creator>
    <dc:date>2015-04-08T18:17:04Z</dc:date>
    <item>
      <title>how to allow some fixed extension go in from outside to inside but not allow go from inside to outside</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668349#M195204</link>
      <description>&lt;P&gt;how to allow some fixed extension go in from outside to inside but not allow go from inside to outside&lt;/P&gt;&lt;P&gt;for example, allow JPEG, MOV, AVI data flow from outside to inside&lt;/P&gt;&lt;P&gt;but not allow JPEG, MOV, AVI files access or upload or get by outside, in another words not from inside to outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to configure?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668349#M195204</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2019-03-12T05:44:59Z</dc:date>
    </item>
    <item>
      <title>Hi, Is it a ASA or any other</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668350#M195205</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it a ASA or any other device? Here is the link that can be helpful:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/100535-asa-8x-regex-config.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 18:00:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668350#M195205</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2015-04-08T18:00:19Z</dc:date>
    </item>
    <item>
      <title>ASA andalso would like to</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668351#M195207</link>
      <description>&lt;P&gt;ASA&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;also would like to know whether general router has this function and how to do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;actually i mean not only web site, for example, in window , share drive, net drive, in linux, you can get file with ftp , or get software, or other kind of methods.&lt;/P&gt;&lt;P&gt;i just afraid hackers can get word file, movie file, or photo&amp;nbsp;if they succeed to pass firewall&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 18:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668351#M195207</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2015-04-08T18:17:04Z</dc:date>
    </item>
    <item>
      <title>You can use zone based</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668352#M195210</link>
      <description>&lt;P&gt;You can use zone based firewall feature of URI inspection:-&lt;/P&gt;&lt;P&gt;Please see in detail at below link:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/ios-firewall/98628-zone-design-guide.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 18:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668352#M195210</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2015-04-08T18:20:39Z</dc:date>
    </item>
    <item>
      <title>zone based web do not have</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668353#M195212</link>
      <description>&lt;P&gt;zone based web do not have file extension to choose, how do it know the extension of file? or type of file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can hacker bypass the file name&amp;nbsp;extension filter of firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i see that ASA has policy ,&amp;nbsp;do ASA have&amp;nbsp;zone based?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 18:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668353#M195212</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2015-04-08T18:51:01Z</dc:date>
    </item>
    <item>
      <title>Hi, The ZBF link sent earlier</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668354#M195214</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ZBF link sent earlier show how we can inspect URI in http request&lt;/P&gt;&lt;P&gt;parameter-map type regex uri_regex_cm&lt;BR /&gt;&amp;nbsp;&amp;nbsp; pattern “.*cmd.exe”&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class-map type inspect http uri_check_cm&lt;BR /&gt;&amp;nbsp;&amp;nbsp; match request uri regex uri_regex_cm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ZBf is the feature on Cisco routers and ASA though concepts are little same but works differently. However it is important that you can be more granular with the protocol (layer 7) inspection only. Like on ASA if you will try to restrict .exe file from a p2p application that won't be possible, But on router you have some application for p2p in NBAR and you can use it file filtering. Please check configuartion example for both devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 21:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668354#M195214</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2015-04-08T21:26:13Z</dc:date>
    </item>
    <item>
      <title>if application is unknown,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668355#M195218</link>
      <description>&lt;P&gt;if application is unknown, how to&amp;nbsp;set?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 00:29:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668355#M195218</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2015-04-09T00:29:51Z</dc:date>
    </item>
    <item>
      <title>well there are some</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668356#M195220</link>
      <description>&lt;P&gt;well there are some limitations with asa and cisco routers as they don't primarily designed for all application. In that case you will need to use other devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 01:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-some-fixed-extension-go-in-from-outside-to-inside/m-p/2668356#M195220</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2015-04-09T01:18:21Z</dc:date>
    </item>
  </channel>
</rss>

