<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FirePower URL HTTP Response in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-url-http-response/m-p/2677172#M44853</link>
    <description>&lt;P&gt;It appears that if I block a URL that is reached only via HTTPS (Facebook in this case) I cannot display an HTTP response that informs the user as to what happened, they just get a connection reset error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that a limitation of the URL filter or do I not have something configured properly?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:24:00 GMT</pubDate>
    <dc:creator>nrunge1</dc:creator>
    <dc:date>2019-03-10T13:24:00Z</dc:date>
    <item>
      <title>FirePower URL HTTP Response</title>
      <link>https://community.cisco.com/t5/network-security/firepower-url-http-response/m-p/2677172#M44853</link>
      <description>&lt;P&gt;It appears that if I block a URL that is reached only via HTTPS (Facebook in this case) I cannot display an HTTP response that informs the user as to what happened, they just get a connection reset error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that a limitation of the URL filter or do I not have something configured properly?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-url-http-response/m-p/2677172#M44853</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2019-03-10T13:24:00Z</dc:date>
    </item>
    <item>
      <title>I'm seeing the same issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-url-http-response/m-p/2677173#M44855</link>
      <description>&lt;P&gt;I'm seeing the same issue with SFR modules for ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd think this is due to the nature of HTTPS filtering that happens on a lower layer than HTTP\Application layer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With HTTPS the connection is getting terminated during HTTPS ( session layer) session set up, thus before HTTP (application layer) has a chance to kick in.&lt;/P&gt;&lt;P&gt;Thus without HTTPS decryption the sfr doesn't get a chance to show custom page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checking thins on a Palo Alto firewall at the moment, they can decrypt HTTPS unlike virtual SFR. The PAs&amp;nbsp; do show custom block page, but only after you accept firewall's&amp;nbsp; spoofed certificate. Obviously when you go to an HTTPS web site the firewall will interept the connection and present a self-sighed cert instead of the real one when decryption is enabled.&lt;/P&gt;&lt;P&gt;If firewall's cert used to sign spoofed cert was trusted this would be seamless for the users.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 02:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-url-http-response/m-p/2677173#M44855</guid>
      <dc:creator>svbakulinkit</dc:creator>
      <dc:date>2015-07-16T02:53:11Z</dc:date>
    </item>
    <item>
      <title>I did not have this behavior</title>
      <link>https://community.cisco.com/t5/network-security/firepower-url-http-response/m-p/2677174#M44858</link>
      <description>&lt;P&gt;I did not have this behavior on the CX platform and I did not do HTTPS decryption on it. I also did not have this behavior on the McAfee Secure Gateway appliance that I used previously and we also did not do any SSL decryption there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get that this is a device that is primarily for IPS and it just happens to do some filtering but for the price hike I would expect a bit more feature parity.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 15:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-url-http-response/m-p/2677174#M44858</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-07-17T15:41:50Z</dc:date>
    </item>
  </channel>
</rss>

