<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Any solutions for URL based routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290757#M344085</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ASA 5505 that has 2 route (1 route connecting to MPLS VPN to HK branch office and 1 route connecting to Internet service provider). As you know, ISP in China blocking many web sites (such as facebook, youtube or etc.). So , I would like to route the traffic when the user in China office would like to browse facebook.com or youtube.com to HK ASA and egress to the internet by NAT. However, all other traffic remain to route to ISP in China, so that the Internet traffic in HK office will not be overload and the user in China can browse facebook.com or youtube.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have researched a topic of regular expression with &lt;SPAN style="font-size: 10pt;"&gt;Modular Policy Framework (MPF). I expected that if the ASA can match the traffic, I can set next hop to HK office's ASA. However, this feature does not support https so that my expectation failed. Because the login page and sometime these web site using https for encryption. I hope URL based routing work on both http and https can work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do anyone have any solutions to resolve this situation? Please kindly provide it to me. I would appreiciate it if you could also provide configuration example with commands. I look forward to hearing from anyone soon. Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Lapson Wong&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:29:55 GMT</pubDate>
    <dc:creator>lapsonwor</dc:creator>
    <dc:date>2019-03-12T02:29:55Z</dc:date>
    <item>
      <title>Any solutions for URL based routing</title>
      <link>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290757#M344085</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ASA 5505 that has 2 route (1 route connecting to MPLS VPN to HK branch office and 1 route connecting to Internet service provider). As you know, ISP in China blocking many web sites (such as facebook, youtube or etc.). So , I would like to route the traffic when the user in China office would like to browse facebook.com or youtube.com to HK ASA and egress to the internet by NAT. However, all other traffic remain to route to ISP in China, so that the Internet traffic in HK office will not be overload and the user in China can browse facebook.com or youtube.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have researched a topic of regular expression with &lt;SPAN style="font-size: 10pt;"&gt;Modular Policy Framework (MPF). I expected that if the ASA can match the traffic, I can set next hop to HK office's ASA. However, this feature does not support https so that my expectation failed. Because the login page and sometime these web site using https for encryption. I hope URL based routing work on both http and https can work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do anyone have any solutions to resolve this situation? Please kindly provide it to me. I would appreiciate it if you could also provide configuration example with commands. I look forward to hearing from anyone soon. Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Lapson Wong&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290757#M344085</guid>
      <dc:creator>lapsonwor</dc:creator>
      <dc:date>2019-03-12T02:29:55Z</dc:date>
    </item>
    <item>
      <title>Any solutions for URL based routing</title>
      <link>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290758#M344086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd rather prefer a proxy solution with automatic proxy configuration (PAC), where specified URLs go to the proxy in HK, everything else bypass proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael &lt;BR /&gt; &lt;BR /&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Aug 2013 08:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290758#M344086</guid>
      <dc:creator>Michael Muenz</dc:creator>
      <dc:date>2013-08-23T08:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Any solutions for URL based routing</title>
      <link>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290759#M344087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What you are trying to do is policy-based routing which is not supported on the ASA.&amp;nbsp; MPF is used only for inspection and QoS type serverices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If using a proxy is not an option, you would need to put in a router that would send the desired traffic over the WAN network.&amp;nbsp; another option, though I would not recommend it, is to find all the IPs of facebook, youtube, etc. and add static routes on the ASA pointing out the WAN interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Aug 2013 10:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290759#M344087</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-08-23T10:31:04Z</dc:date>
    </item>
    <item>
      <title>Any solutions for URL based routing</title>
      <link>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290760#M344088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply. I throught ASA can do the policy based routing based on URL. Now, I understand that I misunderstand something. I hope ASA can do this in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, PAC is a good idear. I prefer to use proxy in this situation. Thx.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Aug 2013 11:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/any-solutions-for-url-based-routing/m-p/2290760#M344088</guid>
      <dc:creator>lapsonwor</dc:creator>
      <dc:date>2013-08-24T11:20:06Z</dc:date>
    </item>
  </channel>
</rss>

