<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Without any additional in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-2911-ios-fireall-configuration-for-https-trafic-block/m-p/2459754#M268002</link>
    <description>&lt;P&gt;Without any additional license or equipment, that's very hard to achieve.&lt;/P&gt;&lt;P&gt;The best way to solve that problem is to use an ASA-NGFW instead of the IOS-router.&lt;/P&gt;&lt;P&gt;If you have to stick with the router you could use Cisco Web Security (CWS) formaly known as Scansafe. But that needs also an additional license.&lt;/P&gt;&lt;P&gt;With only the router you could try some dirty hacks. For example you can deny all unwanted IPs (that of Facebook, Youtube ...) in an ACL. But that is very hard to manage. Or you could control the DNS-communication in a way that your DNS-server return an internal IP of your own webserver for all the unwanted domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But all in all, you are using the wrong tool for that problem.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Mar 2014 10:32:23 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2014-03-28T10:32:23Z</dc:date>
    <item>
      <title>Cisco 2911 IOS Fireall configuration for HTTPS trafic block</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2911-ios-fireall-configuration-for-https-trafic-block/m-p/2459753#M268001</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am configuring Cisco 2911 Sec-k9 router. i am able to block all the sites but not able to block Https Trafic like Facebook,youtube,some unwanted Sites. how to block them. i tried with key word blocking, but still https Sites are opening.&lt;/P&gt;&lt;P&gt;and i want give the full internet&amp;nbsp; access to limited&amp;nbsp; people&lt;/P&gt;&lt;P&gt;Router : Cisco 2911-Seck9 (no aditional licenses)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;Javahar&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2911-ios-fireall-configuration-for-https-trafic-block/m-p/2459753#M268001</guid>
      <dc:creator>rsjavahar</dc:creator>
      <dc:date>2019-03-12T04:00:26Z</dc:date>
    </item>
    <item>
      <title>Without any additional</title>
      <link>https://community.cisco.com/t5/network-security/cisco-2911-ios-fireall-configuration-for-https-trafic-block/m-p/2459754#M268002</link>
      <description>&lt;P&gt;Without any additional license or equipment, that's very hard to achieve.&lt;/P&gt;&lt;P&gt;The best way to solve that problem is to use an ASA-NGFW instead of the IOS-router.&lt;/P&gt;&lt;P&gt;If you have to stick with the router you could use Cisco Web Security (CWS) formaly known as Scansafe. But that needs also an additional license.&lt;/P&gt;&lt;P&gt;With only the router you could try some dirty hacks. For example you can deny all unwanted IPs (that of Facebook, Youtube ...) in an ACL. But that is very hard to manage. Or you could control the DNS-communication in a way that your DNS-server return an internal IP of your own webserver for all the unwanted domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But all in all, you are using the wrong tool for that problem.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2014 10:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-2911-ios-fireall-configuration-for-https-trafic-block/m-p/2459754#M268002</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-03-28T10:32:23Z</dc:date>
    </item>
  </channel>
</rss>

