<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SA520W - blocking URLs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622633#M559615</link>
    <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I purchased a SA520W for my company, and i have some probles for configuring firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to deny access to facebook, youtube and twitter but not for 4 hosts which needs this websites for work.&lt;/P&gt;&lt;P&gt;I tried to configure content filtering &amp;gt; blocking URLs but with this solution, I deny acces for all users.&lt;/P&gt;&lt;P&gt;So, I tried to make IP v4 rules :&lt;/P&gt;&lt;P&gt;The 4 hosts who may access to these websites are 192.168.50.124 to 127&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example :&lt;/P&gt;&lt;P&gt;FROM Zone : LAN&lt;/P&gt;&lt;P&gt;TO : WAN&lt;/P&gt;&lt;P&gt;Service : Any&lt;/P&gt;&lt;P&gt;Action: block always&lt;/P&gt;&lt;P&gt;Source hosts : 192.168.50.32 to 192.168.50.123&lt;/P&gt;&lt;P&gt;destination hosts : 66.220.158.11 (one of the facebook's ip)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but it does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I am looking for an other solution, or maybe my rule is not correctly configured ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your support&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:09:03 GMT</pubDate>
    <dc:creator>info-irfasud</dc:creator>
    <dc:date>2019-03-11T20:09:03Z</dc:date>
    <item>
      <title>SA520W - blocking URLs</title>
      <link>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622633#M559615</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I purchased a SA520W for my company, and i have some probles for configuring firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to deny access to facebook, youtube and twitter but not for 4 hosts which needs this websites for work.&lt;/P&gt;&lt;P&gt;I tried to configure content filtering &amp;gt; blocking URLs but with this solution, I deny acces for all users.&lt;/P&gt;&lt;P&gt;So, I tried to make IP v4 rules :&lt;/P&gt;&lt;P&gt;The 4 hosts who may access to these websites are 192.168.50.124 to 127&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example :&lt;/P&gt;&lt;P&gt;FROM Zone : LAN&lt;/P&gt;&lt;P&gt;TO : WAN&lt;/P&gt;&lt;P&gt;Service : Any&lt;/P&gt;&lt;P&gt;Action: block always&lt;/P&gt;&lt;P&gt;Source hosts : 192.168.50.32 to 192.168.50.123&lt;/P&gt;&lt;P&gt;destination hosts : 66.220.158.11 (one of the facebook's ip)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but it does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I am looking for an other solution, or maybe my rule is not correctly configured ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your support&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622633#M559615</guid>
      <dc:creator>info-irfasud</dc:creator>
      <dc:date>2019-03-11T20:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: SA520W - blocking URLs</title>
      <link>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622634#M559616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to gather a few details on the tests you performed after configuring the rule you mentioned.&lt;/P&gt;&lt;P&gt;According to the rule, traffic is blocked from 192.168.50.32-123 to 66.220.158.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So the test should have been trying &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://66.220.158.11"&gt;http://66.220.158.11&lt;/A&gt;&lt;SPAN&gt; on the browser of one of the systems in the blocked range, and one in the .124-127 range.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Was it accessible from both PCs after configuring this rule, or blocked on both?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Mar 2011 23:55:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622634#M559616</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-03-20T23:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: SA520W - blocking URLs</title>
      <link>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622635#M559617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;after configuring the rule, when i try &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://66.220.158.11"&gt;http://66.220.158.11&lt;/A&gt;&lt;SPAN&gt; on the browser of a system in the blocked range, it's possible to access this website. It's also possible with a system out of the range. So, it's accessible from both PC instead of just the PCs out of the range.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you Shrikant&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Mar 2011 14:50:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622635#M559617</guid>
      <dc:creator>info-irfasud</dc:creator>
      <dc:date>2011-03-21T14:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: SA520W - blocking URLs</title>
      <link>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622636#M559618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For a LAN-WAN rule, you also need to fill in the Source NAT settings. Kindly check if that has been done.&lt;/P&gt;&lt;P&gt;Once you've filled out the settings, please click on Apply and test from both machines again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly, can you edit the rule and allow logging for it, and check if any logs are generated when traffic goes through the device?&lt;/P&gt;&lt;P&gt;Please paste the logs, if any, in the next post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, are there other rules configured between the LAN and WAN interfaces? Maybe one of those rules is getting hit, and thus the rule you've configured for facebook, never comes into play. You could move the facebook rule to the top, so that it is matched before the other rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly let me know if there are any developments, after checking these 3 things.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Mar 2011 15:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622636#M559618</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-03-21T15:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: SA520W - blocking URLs</title>
      <link>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622637#M559619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;What do you mean by "you also need to fill in the Source NAT settings" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to log the rule, but nothing appears in the log table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only other rule is a rule to alow RDP from WAN to LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attach a screenshot to this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to go and will be back on wednesday.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Mar 2011 16:25:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622637#M559619</guid>
      <dc:creator>info-irfasud</dc:creator>
      <dc:date>2011-03-21T16:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: SA520W - blocking URLs</title>
      <link>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622638#M559620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does someone have an idea ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 10:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sa520w-blocking-urls/m-p/1622638#M559620</guid>
      <dc:creator>info-irfasud</dc:creator>
      <dc:date>2011-03-24T10:28:58Z</dc:date>
    </item>
  </channel>
</rss>

