<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TrendMicro Interscan on ASA - block https?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281134#M417984</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to all.&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Aug 2009 08:12:35 GMT</pubDate>
    <dc:creator>dimensyssrl</dc:creator>
    <dc:date>2009-08-05T08:12:35Z</dc:date>
    <item>
      <title>TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281121#M417963</link>
      <description>&lt;P&gt;Is it possible to block urls that link to an https site? I've configured ASA to redirect to it this type of traffic, but it doesn't block it...&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281121#M417963</guid>
      <dc:creator>dimensyssrl</dc:creator>
      <dc:date>2020-02-21T11:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281122#M417965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Different web servers implement redirection in different ways, it would be very difficult to block all of these on the ASA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You want to block HTTPS websites or redirection? This redirection is actually a security enhancement feature, why do you want to block it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jun 2009 06:57:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281122#M417965</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-06-17T06:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281123#M417967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to block certain sites/urls, like for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://www.facebook.com/" target="_blank"&gt;https://www.facebook.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I've configured InterScan to block this domain, but if I try to connect in https it doesn't block this connection (while if I try in http it block connection properly).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 09:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281123#M417967</guid>
      <dc:creator>dimensyssrl</dc:creator>
      <dc:date>2009-06-25T09:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281124#M417969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using Cisco ASA CSC module or a standalone TrendMicro IWSS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Btw what string hvae you configured in the blocking? Have you used wildcards?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 09:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281124#M417969</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-06-25T09:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281125#M417970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm using ASA CSC module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Web (HTTP) --&amp;gt; URL Blocking --&amp;gt; URL keyword (example: 'yyy' string matches all URLs containing 'yyy')&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and inserted there facebook.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, CSC insert *facebook* into Block List.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But then it blocks only http connection and not https ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Into ASA configuration, I've configured http and https traffic to be redirected to CSC...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 09:31:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281125#M417970</guid>
      <dc:creator>dimensyssrl</dc:creator>
      <dc:date>2009-06-25T09:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281126#M417972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anyone that can help me?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2009 09:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281126#M417972</guid>
      <dc:creator>dimensyssrl</dc:creator>
      <dc:date>2009-07-23T09:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281127#M417973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It works perfectly fine on our Trendmicro IWSS server, here is a sample block message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IWSS Security Event&lt;/P&gt;&lt;P&gt;Access to this URL is currently restricted due to a blocking rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL: &lt;A class="jive-link-custom" href="http://www.apple.com:443" target="_blank"&gt;www.apple.com:443&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Rule: Block URLs of type Administrator-defined&lt;/P&gt;&lt;P&gt;If you feel you have reached this message in error, please contact your network administrator. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please can you send me the screenshot of the page where you configured the block URLS in the CSC  module?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Jul 2009 05:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281127#M417973</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-07-25T05:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281128#M417974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here it is.&lt;/P&gt;&lt;P&gt;There is asa traffic redirection configuration also.&lt;/P&gt;&lt;P&gt;My ip is into network 10.168.32.0/24.&lt;/P&gt;&lt;P&gt;If I try &lt;A class="jive-link-custom" href="https://www.facebook.com/" target="_blank"&gt;https://www.facebook.com/&lt;/A&gt; it doesn't block me.&lt;/P&gt;&lt;P&gt;If I try &lt;A class="jive-link-custom" href="http://www.facebook.com/" target="_blank"&gt;http://www.facebook.com/&lt;/A&gt; it block me.&lt;/P&gt;&lt;P&gt;Thanks and sorry for the delay in my reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2009 08:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281128#M417974</guid>
      <dc:creator>dimensyssrl</dc:creator>
      <dc:date>2009-07-29T08:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281129#M417975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't understand why this happens... Configuration is the same for http or https traffic...&lt;/P&gt;&lt;P&gt;Is there anybody out there that can explain me why?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2009 09:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281129#M417975</guid>
      <dc:creator>dimensyssrl</dc:creator>
      <dc:date>2009-07-30T09:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281130#M417976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know the csc trenmicro module does not do https, only http. Maybe you can confirm this with TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Jul 2009 20:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281130#M417976</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2009-07-31T20:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281131#M417977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/csc/csc60/administration/guide/csc1.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/csc/csc60/administration/guide/csc1.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..."Trend Micro InterScan for Cisco CSC SSM (Content Security and Control Security Services Module) provides an all-in-one antivirus and spyware management solution for your network. This guide provides a conceptual explanation of how to manage the CSC SSM, which is resident in your Cisco appliance to do the following: &lt;/P&gt;&lt;P&gt;â&amp;#128;¢Detect and take action on viruses, worms, Trojans, and other threats in your SMTP, POP3, HTTP, and FTP network traffic &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note Traffic utilizing other protocols, such as HTTPS, is not scanned by CSC SSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Block compressed or very large files that exceed specified parameters &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Scan for and remove spyware, adware, and other types of grayware ..."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Jul 2009 23:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281131#M417977</guid>
      <dc:creator>dfarrell</dc:creator>
      <dc:date>2009-07-31T23:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281132#M417979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;So, this message what means?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=General&amp;amp;topicID=.ee6e1f8&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cd35b61/5#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=General&amp;amp;topicID=.ee6e1f8&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cd35b61/5#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2009 07:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281132#M417979</guid>
      <dc:creator>dimensyssrl</dc:creator>
      <dc:date>2009-08-05T07:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281133#M417981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Daniele&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mentioned in my post that it works on a standalone Trendmicro IWSS server, meaning we have the IWSS software running on our proxy servers (via proxy chaining). HTTPS filtering works on the Standalone IWSS software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(As it appears from the documentation) Cisco/Trend Micro have disabled this HTTPS filtering capability in the CSC Module's IWSS software. Only Cisco/TM can comment on this, but it could be due to performance issues, CSC topology (traffic via back plane) etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2009 07:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281133#M417981</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-08-05T07:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: TrendMicro Interscan on ASA - block https??</title>
      <link>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281134#M417984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to all.&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2009 08:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trendmicro-interscan-on-asa-block-https/m-p/1281134#M417984</guid>
      <dc:creator>dimensyssrl</dc:creator>
      <dc:date>2009-08-05T08:12:35Z</dc:date>
    </item>
  </channel>
</rss>

