<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 8.4.4 filter url using hostname in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005686#M401112</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank y ou Jouni and Karsten. I'm aware of the use in access-lists but was hoping there was some way to apply the fqdn feature to the filter url command. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Aug 2012 12:35:44 GMT</pubDate>
    <dc:creator>vpersaud001</dc:creator>
    <dc:date>2012-08-08T12:35:44Z</dc:date>
    <item>
      <title>ASA 8.4.4 filter url using hostname</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005683#M401109</link>
      <description>&lt;P&gt;Hello ... is there any way to apply hostname or object network in the syntax? &lt;/P&gt;&lt;P&gt;The command gives the option to use hostname or A.B.C.D but doesn't accept the hostname&lt;/P&gt;&lt;P&gt;PIX1(config)# filter url except 0.0.0.0 0.0.0.0 ?&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; Hostname or A.B.C.D&amp;nbsp; The address of foreign/external host which is&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination for connections requiring filtering&lt;/P&gt;&lt;P&gt;Can an FQDN be used as a foreign/external host? &lt;/P&gt;&lt;P&gt;Thanks. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005683#M401109</guid>
      <dc:creator>vpersaud001</dc:creator>
      <dc:date>2019-03-11T23:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.4.4 filter url using hostname</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005684#M401110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if I have every used the command you are using in your example. Is it related to using an external server for the filtering?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is though an option to use FQDN on the access-list if you are running atleast 8.4(2) on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example a Facebook block could be configured like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;DNS server-group DefaultDNS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; name-server x.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; name-server y.y.y.y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network FACEBOOK-FQDN&lt;/P&gt;&lt;P&gt; fqdn www.facebook.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSIDE-IN remark Block Facebook&lt;/P&gt;&lt;P&gt;access-list INSIDE-IN extended deny ip any object FACEBOOK-FQDN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then again the above configuration would not completely block Facebook for example since the destination address keeps changing. (Would have to resort to dropping the HTTP connections, dropping the DNS replys, dropping the traffic on the basis of the destination IP address etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2012 06:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005684#M401110</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-08-08T06:56:52Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4.4 filter url using hostname</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005685#M401111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This feature is very good explained in a supportforum-doc:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-17014"&gt;https://supportforums.cisco.com/docs/DOC-17014&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2012 07:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005685#M401111</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-08-08T07:25:18Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4.4 filter url using hostname</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005686#M401112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank y ou Jouni and Karsten. I'm aware of the use in access-lists but was hoping there was some way to apply the fqdn feature to the filter url command. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2012 12:35:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-filter-url-using-hostname/m-p/2005686#M401112</guid>
      <dc:creator>vpersaud001</dc:creator>
      <dc:date>2012-08-08T12:35:44Z</dc:date>
    </item>
  </channel>
</rss>

