<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to block porn site with PIX or ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-block-porn-site-with-pix-or-asa/m-p/1432211#M417451</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We like to block the porn site + few url in our IT Infrastructure. How can we achieve this with PIX 515 or Cisco ASA?&lt;/P&gt;&lt;P&gt;If it's achievable by Cisco ASA then which edition ASA can be use ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nilesh&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:00:28 GMT</pubDate>
    <dc:creator>nilesh_sawant</dc:creator>
    <dc:date>2020-02-21T12:00:28Z</dc:date>
    <item>
      <title>How to block porn site with PIX or ASA</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-porn-site-with-pix-or-asa/m-p/1432211#M417451</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We like to block the porn site + few url in our IT Infrastructure. How can we achieve this with PIX 515 or Cisco ASA?&lt;/P&gt;&lt;P&gt;If it's achievable by Cisco ASA then which edition ASA can be use ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nilesh&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-porn-site-with-pix-or-asa/m-p/1432211#M417451</guid>
      <dc:creator>nilesh_sawant</dc:creator>
      <dc:date>2020-02-21T12:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to block porn site with PIX or ASA</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-porn-site-with-pix-or-asa/m-p/1432212#M417454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nilesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a couple of options that you can consider here.&amp;nbsp; If you have an ASA5510 or greater, you can consider purchasing a CSC module.&amp;nbsp; The CSC module will allow you to select various categories and dynamically filter sensitive sites - including pornography, hacking, and other malicious categories.&amp;nbsp; With the release of CSC 6.3+, you can also integrate the filtering and URL-blocking functionality of this product with Active Directory.&amp;nbsp; Depending on the user, you can filter what user has access to what websites or categories of websites.&amp;nbsp; Please contact your Cisco Account Team or reseller if this is something that you would be interested in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you just want to filter certain websites manually, you can enable 'inspect http'.&amp;nbsp; Once you have enabled 'inspect http', you can reset particular connections based on the Layer 4-7 content of the packet.&amp;nbsp; For instance, consider the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regex badsite "www.badsite.com"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect http_policy&lt;/P&gt;&lt;P&gt; match request header host regex badsite&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http http_policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there are a number of sites that you are concerned with, you can also match off of a class-map of regular expressions.&amp;nbsp; Unfortunately with this approach, the detail in your regex will determine how successful your filter will be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASDM has a wonderful Regex testing feature that will assist in developing the appropriate regex for your filter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jun 2010 22:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-porn-site-with-pix-or-asa/m-p/1432212#M417454</guid>
      <dc:creator>Kevin Redmon</dc:creator>
      <dc:date>2010-06-29T22:40:08Z</dc:date>
    </item>
  </channel>
</rss>

