<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: To check if url is allowed by ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178540#M356968</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mask is 255.240.0.0 .You are right so it will block whole subnet from 172.16&amp;nbsp; to 172.31.0.0.&lt;/P&gt;&lt;P&gt;you are very good in firewalls.&lt;/P&gt;&lt;P&gt;Unfortunately i can not config any changes on ASA&amp;nbsp; to test the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&amp;nbsp; for helping me out .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Feb 2013 22:59:09 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2013-02-07T22:59:09Z</dc:date>
    <item>
      <title>To check if url is allowed by ASA</title>
      <link>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178534#M356962</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to download drivers from HP website for a printer.&lt;/P&gt;&lt;P&gt;Traffic goes via ASA&amp;nbsp; to the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to rule out if ASA is blocking&amp;nbsp; or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what i did &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://h20000.www2.hp.com/bizsupport/TechSupport/SoftwareIndex.jsp?lang=en&amp;amp;cc=us&amp;amp;prodNameId=3644759&amp;amp;prodTypeId=18972&amp;amp;prodSeriesId=3644758&amp;amp;swLang=8&amp;amp;taskId=135&amp;amp;swEnvOID=4063#78266" target="_blank"&gt;http://h20000.www2.hp.com/bizsupport/TechSupport/SoftwareIndex.jsp?lang=en&amp;amp;cc=us&amp;amp;prodNameId=3644759&amp;amp;prodTypeId=18972&amp;amp;prodSeriesId=3644758&amp;amp;swLang=8&amp;amp;taskId=135&amp;amp;swEnvOID=4063#78266&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://h20000.www2.hp.com/bizsupport/TechSupport/SoftwareDownloadEventHandler.jsp?redirectReason=SWD_FTP_Request&amp;amp;swItem=ds-99376-4&amp;amp;prodSeriesId=3644758&amp;amp;prodLine=6A&amp;amp;targetPage=ftp%3A%2F%2Fftp.hp.com%2Fpub%2Fsoftlib%2Fsoftware12%2FCOL40842%2Fds-99376-4/upd-ps-x64-5.6.0.14430.exe&amp;amp;filesize=18802560" target="_blank"&gt;http://h20000.www2.hp.com/bizsupport/TechSupport/SoftwareDownloadEventHandler.jsp?redirectReason=SWD_FTP_Request&amp;amp;swItem=ds-99376-4&amp;amp;prodSeriesId=3644758&amp;amp;prodLine=6A&amp;amp;targetPage=ftp%3A%2F%2Fftp.hp.com%2Fpub%2Fsoftlib%2Fsoftware12%2FCOL40842%2Fds-99376-4/upd-ps-x64-5.6.0.14430.exe&amp;amp;filesize=18802560&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On first url when you click on download then 2&lt;SUP&gt;nd&lt;/SUP&gt; url shows&amp;nbsp; internet explorer&amp;nbsp; can not display the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IS ASA&amp;nbsp; blocking something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178534#M356962</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T00:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: To check if url is allowed by ASA</title>
      <link>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178535#M356963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second link atleast works for me and starts a file download.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would open ASDM and go to the Monitor/Logging section and open the log window. I would then enter the LAN host IP address you are using to access the site to the section that applies the filter for the logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I would click the link to download the file and watch the ASA logs what happens to the connections from your host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It tries to download the file with FTP. Have you allowed FTP connections from the host to the Internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 18:55:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178535#M356963</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-07T18:55:54Z</dc:date>
    </item>
    <item>
      <title>To check if url is allowed by ASA</title>
      <link>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178536#M356964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put lan host IP on filter by&amp;nbsp; then i see nothing in fw logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;its blank empty page.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 20:31:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178536#M356964</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-02-07T20:31:41Z</dc:date>
    </item>
    <item>
      <title>To check if url is allowed by ASA</title>
      <link>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178537#M356965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see the connection logs IF&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If the connection is coming all the way to the ASA&lt;/LI&gt;&lt;LI&gt;If there is nothing blocking the traffic in between the user and the ASA&lt;/LI&gt;&lt;LI&gt;You have set the ASDM logging level to atleast "informational"&lt;UL&gt;&lt;LI&gt;logging asdm informational&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;You have not disabled some logging messages&lt;UL&gt;&lt;LI&gt;You should get a list of the disabled log messages with the "show run logging" command on the CLI of the AS&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the most certain way to see whats going through the ASA would be to configure a capture on the ASA but this might be a bit more time consuming.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have witnessed the ASDM side logging sometimes showing the connection logs very very late compared to the time when you actually test some connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also naturally if you want to make sure that the ASA is not blocking any connection for the host you can temporarily insert a rule on the interface ACL behind which the host is. Inserting a rule one the "line 1" which permits all traffic from that host would make sure that nothing gets blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But all in all, you should really see something in the logs if the connection is coming through the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 20:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178537#M356965</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-07T20:39:27Z</dc:date>
    </item>
    <item>
      <title>To check if url is allowed by ASA</title>
      <link>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178538#M356966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to find out by packet tracer that FTP is not allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My PC&amp;nbsp; IP is say 172.31.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran the packet tracer choosing my source IP as PC&amp;nbsp; IP and source interface as say Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet tracer showed me&amp;nbsp; in animation &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network ACL lookup&amp;nbsp; flwo lookup route lookup ACL lookup is all&amp;nbsp; right but&amp;nbsp; on outside it shows red x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under phase&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access list and Result had X mark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; under ACL&amp;nbsp; config &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it showed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group Network_01 in&amp;nbsp; interface Network&lt;/P&gt;&lt;P&gt;access-list Network_01 extended deny tcp 172.16.0.0 x.x.x.x any eq ftp log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so does this ACL means that drop FTP traffic as it enters the Inside interface of ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second this to know is that MY PC&amp;nbsp; IP 172.31 and ASA ACL that shows deny IP subnet 172.16&amp;nbsp; they both are in different subnets and still ACL is blocking the FTP?&lt;/P&gt;&lt;P&gt;Can you please explain me how this ACL is working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 22:30:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178538#M356966</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-02-07T22:30:36Z</dc:date>
    </item>
    <item>
      <title>To check if url is allowed by ASA</title>
      <link>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178539#M356967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would seem that the ACL is possibly blocking the FTP traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You say the networks are different but you didnt include the network mask thats in the ACL. What is the network mask &lt;STRONG&gt;x.x.x.x&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice that if the mask is &lt;STRONG&gt;/12&lt;/STRONG&gt; or &lt;STRONG&gt;255.240.0.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then it would mean the whole private IP address range of &lt;STRONG&gt;172.16.0.0 - 172.31.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Therefore it would actually block the connections even from host 172.31.x.x as you can see&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you enter the configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list Network_01 line 1 permit tcp host 172.31.x.x any eq ftp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then it will enter the rule to the top of the ACL. Therefore it will be the first rule matched when traffic enters that firewall interface. And it will therefore allow the FTP connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could try adding that line and testing the connection again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 22:44:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178539#M356967</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-07T22:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: To check if url is allowed by ASA</title>
      <link>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178540#M356968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mask is 255.240.0.0 .You are right so it will block whole subnet from 172.16&amp;nbsp; to 172.31.0.0.&lt;/P&gt;&lt;P&gt;you are very good in firewalls.&lt;/P&gt;&lt;P&gt;Unfortunately i can not config any changes on ASA&amp;nbsp; to test the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&amp;nbsp; for helping me out .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 22:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-check-if-url-is-allowed-by-asa/m-p/2178540#M356968</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-02-07T22:59:09Z</dc:date>
    </item>
  </channel>
</rss>

