<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection on ASA with SmartFilter in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/https-inspection-on-asa-with-smartfilter/m-p/1469621#M700623</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The smartfilter blocks https doing a reverse lookup for all illegit urls.&lt;/P&gt;&lt;P&gt;In other words when it sees the ip address you are https-ing to it checks what domain the ip address belongs and then decides if it needs to block.&lt;/P&gt;&lt;P&gt;The ASA does not know the url because the http has the URL encrypted and so it can't log it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 May 2010 18:45:48 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2010-05-14T18:45:48Z</dc:date>
    <item>
      <title>HTTPS inspection on ASA with SmartFilter</title>
      <link>https://community.cisco.com/t5/network-security/https-inspection-on-asa-with-smartfilter/m-p/1469620#M700610</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got an ASA5505 with URL-filtering through SmartFilter.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HTTP ist working fine. HTTPS unfortunately can only be blocked on the SmartFilter with the IP address (e.g. &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://70.42.13.100" target="_blank"&gt;https://70.42.13.100&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and not with the domain-name (e.g. &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/" target="_blank"&gt;https://www.cisco.com/&lt;/A&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;On the ASA, the SyslogID 304001 shows only&amp;nbsp;&amp;nbsp; &amp;lt;inside client ip&amp;gt; Accessed URL 70.42.13.10:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://70.42.13.10/" target="_blank"&gt;https://70.42.13.10/&lt;/A&gt;&lt;SPAN&gt; and this is, what the&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;SmartFilter are checking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I tell the ASA to log/send the URL name to the SmartFilter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Norbert&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:45:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-inspection-on-asa-with-smartfilter/m-p/1469620#M700610</guid>
      <dc:creator>alig.norbert</dc:creator>
      <dc:date>2019-03-11T17:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection on ASA with SmartFilter</title>
      <link>https://community.cisco.com/t5/network-security/https-inspection-on-asa-with-smartfilter/m-p/1469621#M700623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The smartfilter blocks https doing a reverse lookup for all illegit urls.&lt;/P&gt;&lt;P&gt;In other words when it sees the ip address you are https-ing to it checks what domain the ip address belongs and then decides if it needs to block.&lt;/P&gt;&lt;P&gt;The ASA does not know the url because the http has the URL encrypted and so it can't log it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 18:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-inspection-on-asa-with-smartfilter/m-p/1469621#M700623</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-05-14T18:45:48Z</dc:date>
    </item>
  </channel>
</rss>

