<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992826#M439553</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA can not inspect HTTPS. You could deny name-resolution for facebook.com or use a proxy-server that can inspect HTTPS-traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jul 2012 13:36:48 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2012-07-12T13:36:48Z</dc:date>
    <item>
      <title>Cisco ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992824#M439551</link>
      <description>&lt;P&gt;I have&amp;nbsp; cisco ASA5510 firewall&amp;nbsp; using in my network but&amp;nbsp; unable to bolck Url's&amp;nbsp; unwanted.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;can i block the &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://facebook.com" target="_blank"&gt;https://facebook.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; on the asa by using regular exp.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Saroj&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992824#M439551</guid>
      <dc:creator>saroj pradhan</dc:creator>
      <dc:date>2019-03-11T23:30:14Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992825#M439552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the sample config for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940e04.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940e04.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 13:02:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992825#M439552</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-07-12T13:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992826#M439553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA can not inspect HTTPS. You could deny name-resolution for facebook.com or use a proxy-server that can inspect HTTPS-traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 13:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992826#M439553</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-07-12T13:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992827#M439554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can not block https as the "get-request' for the facebook.com will be encypted. However you can use ASA to block facebook based on your DNS request in case you dns request is passing through the ASA. ASA can inspect that DNS packet and based on regex you can deny that dns request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this way user will never be able to connect to facebook.com (3-way handshake).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but if you are using an internal DNS server, ASA won't be receiving the request if it is in same LAN segment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dinkar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 22:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510/m-p/1992827#M439554</guid>
      <dc:creator>Dinkar Sharma</dc:creator>
      <dc:date>2012-07-12T22:03:04Z</dc:date>
    </item>
  </channel>
</rss>

