<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Redirect denied traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352136#M270962</link>
    <description>&lt;P&gt;Hi. Is it possible to redirect denied traffic in Cisco ASA?&lt;/P&gt;&lt;P&gt;For example if a user is trying to access an HTTP page which is denied to him by an access-list, then that user is redirected to another HTTP webpage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ultimate goal is to notify the user that the resource he is trying to access is actually denied by the access-list and not because of a network/service outage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any reasonable solution to this problem? thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:35:22 GMT</pubDate>
    <dc:creator>heiki saaver</dc:creator>
    <dc:date>2019-03-12T03:35:22Z</dc:date>
    <item>
      <title>Redirect denied traffic</title>
      <link>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352136#M270962</link>
      <description>&lt;P&gt;Hi. Is it possible to redirect denied traffic in Cisco ASA?&lt;/P&gt;&lt;P&gt;For example if a user is trying to access an HTTP page which is denied to him by an access-list, then that user is redirected to another HTTP webpage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ultimate goal is to notify the user that the resource he is trying to access is actually denied by the access-list and not because of a network/service outage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any reasonable solution to this problem? thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352136#M270962</guid>
      <dc:creator>heiki saaver</dc:creator>
      <dc:date>2019-03-12T03:35:22Z</dc:date>
    </item>
    <item>
      <title>Redirect denied traffic</title>
      <link>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352137#M270963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine this would be the job of some other device other than the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ASA denies the traffic it then thats it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only thing silimiar I can think of right now would be to configure Cut Through Proxy which would ask the user for authentication when he attempts to connection to certain destination with certain port. You could also configure a message on teh ASA that would be printed to the user when the ASA shows the authentication page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one document&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080ba6110.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080ba6110.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is plenty of documents online about this subject though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 16:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352137#M270963</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-01-24T16:04:48Z</dc:date>
    </item>
    <item>
      <title>Redirect denied traffic</title>
      <link>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352138#M270964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I think the cut-through proxy will work good enough.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good job Jouni, thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 07:39:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352138#M270964</guid>
      <dc:creator>heiki saaver</dc:creator>
      <dc:date>2014-01-27T07:39:37Z</dc:date>
    </item>
    <item>
      <title>Redirect denied traffic</title>
      <link>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352139#M270965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;unfortunately it seems that the cut-through proxy cant be applied to Anyconnect VPN users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the topic I started &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/4150921#4150921"&gt;https://supportforums.cisco.com/message/4150921#4150921&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 07:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-denied-traffic/m-p/2352139#M270965</guid>
      <dc:creator>heiki saaver</dc:creator>
      <dc:date>2014-02-03T07:39:41Z</dc:date>
    </item>
  </channel>
</rss>

