<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Content Security Module (Anti-X) issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867894#M421584</link>
    <description>&lt;P&gt;Is there a way to configure the Anti-X module such as I can filter the web content based on source VLAN or subnet? I need to implement something like that and can?t find how to do it.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:41:14 GMT</pubDate>
    <dc:creator>rommel-peraza</dc:creator>
    <dc:date>2020-02-21T09:41:14Z</dc:date>
    <item>
      <title>ASA Content Security Module (Anti-X) issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867894#M421584</link>
      <description>&lt;P&gt;Is there a way to configure the Anti-X module such as I can filter the web content based on source VLAN or subnet? I need to implement something like that and can?t find how to do it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867894#M421584</guid>
      <dc:creator>rommel-peraza</dc:creator>
      <dc:date>2020-02-21T09:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Content Security Module (Anti-X) issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867895#M421585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic for CSC inspection is done using the Modular Policy Framework commands to create a service-policy&lt;/P&gt;&lt;P&gt;General modular policy info is here&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/mpc.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/mpc.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The service policy you create sends traffic to the CSC for inspection&lt;/P&gt;&lt;P&gt;The service policy identifies traffic using one or more class-maps &lt;/P&gt;&lt;P&gt;Class-maps can use an access-list to match interesting traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it's up to how creative you can get with your access-list really. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Info here should be of some help&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/ssm.html#wp1058664" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/ssm.html#wp1058664&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's an extremely basic example to hopefully get you going that inspects only http traffic initiated from the 10.1.1.0/24 subnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; access-list MATCH_CSC extended permit ip 10.1.1.0 255.255.255.0 any eq http&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; class-map MATCH_CSC_CLASS&lt;/P&gt;&lt;P&gt;  match access-list MATCH_CSC &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; policy-map CSC_POLICY&lt;/P&gt;&lt;P&gt;  class MATCH_CSC_CLASS&lt;/P&gt;&lt;P&gt;   csc fail-close&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; service-policy CSC_POLICY global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2007 09:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867895#M421585</guid>
      <dc:creator>GRAEME DANIELSON</dc:creator>
      <dc:date>2007-09-17T09:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Content Security Module (Anti-X) issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867896#M421586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer, I maybe didn?t write well what I really need. I need that the all traffic passing through the ASA to be inspected by the CSC and it?s already done actually using ACL and policy maps as you say; now once the traffic is sent it to the CSC I need to "clasify" the filters based on the source Vlan or Subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sales manager from vlan 2 can see sport news on the web but a Human Resources employee(from vlan 3) only can get in the Organization web site and financial web pages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can it be done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2007 13:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867896#M421586</guid>
      <dc:creator>rommel-peraza</dc:creator>
      <dc:date>2007-09-17T13:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Content Security Module (Anti-X) issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867897#M421587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK I don't believe there is that level of granular control within the CSC.  The closest I think would be to exclude selected internal IP address ranges from all URL filtering i.e. they can go anywhere.&lt;/P&gt;&lt;P&gt;I think you need something like a Websense service which the ASA can query for it's URL filtering decisions. Not sure about it's co-existence with the CSC though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2007 00:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867897#M421587</guid>
      <dc:creator>GRAEME DANIELSON</dc:creator>
      <dc:date>2007-09-18T00:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Content Security Module (Anti-X) issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867898#M421588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2007 05:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-content-security-module-anti-x-issue/m-p/867898#M421588</guid>
      <dc:creator>rommel-peraza</dc:creator>
      <dc:date>2007-09-18T05:58:38Z</dc:date>
    </item>
  </channel>
</rss>

