<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA-CX blocking Facebook apps... with https://? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-cx-blocking-facebook-apps-with-https/m-p/2156914#M356629</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As initial action plan : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- you need to configure a URL object for Facebook if it was not configured :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/2/1/165127-url.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Enable Decryption policy , Device à Decryption and configure a certificate , either a self-signed one or import one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Then&amp;nbsp; need to configure the Decryption policy for Facebook : &lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1. Policy to deny Facebook under Access section :&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/3/1/165131-1.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Policy Under decryption section&amp;nbsp; : &lt;/P&gt;&lt;P&gt; &lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/3/1/165132-2.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you have any questions or concners &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Nov 2013 05:15:37 GMT</pubDate>
    <dc:creator>Fadil Kadrat</dc:creator>
    <dc:date>2013-11-04T05:15:37Z</dc:date>
    <item>
      <title>ASA-CX blocking Facebook apps... with https://?</title>
      <link>https://community.cisco.com/t5/network-security/asa-cx-blocking-facebook-apps-with-https/m-p/2156912#M356627</link>
      <description>&lt;P&gt;Hello pro's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been playing around with the ASA-CX capability of blocking URLs or Facebook photos or games through policies. It works like a charm, but I encountered issues when I was using https; my policies stopped working. Also I was not seeing reports of the URLs I accessed using a secure connection (https)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, after I enabled Decryption (Device-&amp;gt;Decryption-&amp;gt;Enable Decryption policies) I started seeing the reports of the URLs but still my policies are not working. The feature of blocking only certain apps or activities inside a web that could be perfectly used for business (such as facebook) is excelent, but if the users can go around as easily as using https, I don't see the point. I am sure I am missing some configuration steps... Could anybody please shed some light on this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:00:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cx-blocking-facebook-apps-with-https/m-p/2156912#M356627</guid>
      <dc:creator>Javier Aquino</dc:creator>
      <dc:date>2019-03-12T01:00:42Z</dc:date>
    </item>
    <item>
      <title>ASA-CX blocking Facebook apps... with https://?</title>
      <link>https://community.cisco.com/t5/network-security/asa-cx-blocking-facebook-apps-with-https/m-p/2156913#M356628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just updating...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was not able to play with the Demo, but I figured out that I needed to first configure decrypting policies, then accept the ASA CX certificate on the client machine... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately I had no more time to check it, I had to give the borrowed ASA back.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2013 17:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cx-blocking-facebook-apps-with-https/m-p/2156913#M356628</guid>
      <dc:creator>Javier Aquino</dc:creator>
      <dc:date>2013-03-05T17:11:50Z</dc:date>
    </item>
    <item>
      <title>ASA-CX blocking Facebook apps... with https://?</title>
      <link>https://community.cisco.com/t5/network-security/asa-cx-blocking-facebook-apps-with-https/m-p/2156914#M356629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As initial action plan : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- you need to configure a URL object for Facebook if it was not configured :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/2/1/165127-url.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Enable Decryption policy , Device à Decryption and configure a certificate , either a self-signed one or import one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Then&amp;nbsp; need to configure the Decryption policy for Facebook : &lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1. Policy to deny Facebook under Access section :&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/3/1/165131-1.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Policy Under decryption section&amp;nbsp; : &lt;/P&gt;&lt;P&gt; &lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/3/1/165132-2.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you have any questions or concners &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 05:15:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cx-blocking-facebook-apps-with-https/m-p/2156914#M356629</guid>
      <dc:creator>Fadil Kadrat</dc:creator>
      <dc:date>2013-11-04T05:15:37Z</dc:date>
    </item>
  </channel>
</rss>

