<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: bock some urls? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495617#M708806</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raphael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank's for your Herp - I had use the wrong interface!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if I activat the url filter - I'm not able to conect to extern Terminal Servern. - Do I have to activat something more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank's&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Jun 2010 06:47:07 GMT</pubDate>
    <dc:creator>it-interschalt</dc:creator>
    <dc:date>2010-06-15T06:47:07Z</dc:date>
    <item>
      <title>bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495613#M708799</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we use some cisco 2811 router and I have to block some url sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to do this with the cisco 2811 router - and how can I do it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:59:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495613#M708799</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2019-03-11T17:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495614#M708800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use Trend Micro or Websense database to do content filtering but if you just have only a few URL to bloc you could do by configuring URL locally. You can use the urlfiltering feature of both IOS firewalls: CBAC or ZBF, but it would be nice to have some firewall knowledge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just answered a similar thread couple of days ago but it's in french let me know if additional translation would be useful &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; You can see in that thread the configuration example to use both firewalls to do&amp;nbsp; local URL filtering only (first with CBAC and second with ZBF):&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/message/3118200#3118200"&gt;https://supportforums.cisco.com/message/3118200#3118200&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is config doc for CBAC:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://cisco.biz/en/US/products/ps5855/products_configuration_example09186a0080ab4ddb.shtml"&gt;http://cisco.biz/en/US/products/ps5855/products_configuration_example09186a0080ab4ddb.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is for ZBF, this is a good doc found on this forum:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-8028"&gt;https://supportforums.cisco.com/docs/DOC-8028#_Configuration_with_Static_Filtering_&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is supported on 2800 but you may need to check IOS version and featureset, ZBF for example requieres 12.4.(20)T or later as mentioned in the above doc, I think CBAC urlfiltering is available way before this the doc mention it's working in "12.4" so I suppose this means it's available in 12.4 mainline.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Raphael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jun 2010 14:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495614#M708800</guid>
      <dc:creator>Raphael Wouters</dc:creator>
      <dc:date>2010-06-14T14:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495615#M708802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raphael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this the enough or the config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R0&amp;gt;en&lt;BR /&gt;R0#conf t&lt;BR /&gt;Enter configuration commands, one per line.&amp;nbsp; End with CNTL/Z.&lt;BR /&gt;R0(config)#ip inspect name TEST http urlfilter&lt;BR /&gt;R0(config)#ip urlfilter allow-mode on&lt;BR /&gt;R0(config)#ip urlfilter exclusive-domain deny &lt;A href="https://community.cisco.com/www.denyme.com" target="_blank"&gt;www.denyme.com&lt;/A&gt;&lt;BR /&gt;R0(config)#ip urlfilter audit-trail&lt;BR /&gt;R0(config)#interface FastEthernet0/0&lt;BR /&gt;R0(config-if)#ip inspect TEST out&lt;BR /&gt;R0(config-if)#end&lt;BR /&gt;R0#&lt;/P&gt;&lt;P&gt;or do I have to change something more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because If I try to reache "&lt;A href="http://www.denyme.com"&gt;www.denyme.com&lt;/A&gt; " I can access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank's for you anwser&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jun 2010 15:00:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495615#M708802</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-06-14T15:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495616#M708804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should be enough yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure to configure "ip inspect TEST out" on all outside interface (facing the WAN), by default all other interfaces will be considered as inside.&lt;/P&gt;&lt;P&gt;-OR- to configure&amp;nbsp; "ip inspect TEST in" on all the inside interfaces facing the LAN and by default all other interfaces will be considered as outside.&lt;/P&gt;&lt;P&gt;Then the connections from inside to outside should be reset for the denied URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is fast 0/0 used for? Where are your WAN and LAN interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Raphael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jun 2010 15:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495616#M708804</guid>
      <dc:creator>Raphael Wouters</dc:creator>
      <dc:date>2010-06-14T15:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495617#M708806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raphael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank's for your Herp - I had use the wrong interface!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if I activat the url filter - I'm not able to conect to extern Terminal Servern. - Do I have to activat something more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank's&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jun 2010 06:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495617#M708806</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-06-15T06:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495618#M708813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above configuration should only match HTTP sessions, and with "audit-trail" on you should see a log for each failure attempt.&lt;/P&gt;&lt;P&gt;How do you connect to your Terminal Server?&lt;/P&gt;&lt;P&gt;Can you check the logs and "&lt;SPAN style="font-family: 'courier new', courier;"&gt;show ip inspect session details&lt;/SPAN&gt;" just after a failure attempt? You could add this to have more logs, but don't forget to remove it later as this can be very chatty: &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip inspect audit-trail&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter audit-trail&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall should not inspect anything else than HTTP, all other incoming traffic should pass, and with "&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter allow-mode on&lt;/SPAN&gt;" all the http traffic that doesn't match the exclusive-domain rule will pass.&lt;/P&gt;&lt;P&gt;So if you remove all the interface configuration "ip inspect TEST out" only you confirm it's working fine?&lt;/P&gt;&lt;P&gt;You can maybe post a sample of your config for the firewall, something like &lt;SPAN style="font-family: 'courier new', courier;"&gt;show run | i inspect|url|interface&lt;/SPAN&gt;&amp;nbsp; ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jun 2010 07:57:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495618#M708813</guid>
      <dc:creator>Raphael Wouters</dc:creator>
      <dc:date>2010-06-15T07:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495619#M708814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Raohael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is my original config (with show run | i inspect|url|interface)&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;show run | i inspect|url|interface&lt;BR /&gt;ip inspect name FW appfw FW&lt;BR /&gt;ip inspect name FW tcp&lt;BR /&gt;ip inspect name FW udp&lt;BR /&gt;ip inspect name FW ftp&lt;BR /&gt;ip inspect name FW http&lt;BR /&gt;ip inspect name sdm_ins_in_100 tcp&lt;BR /&gt;ip inspect name sdm_ins_in_100 udp&lt;BR /&gt;ip inspect name sdm_ins_out_100 tcp&lt;BR /&gt;ip inspect name sdm_ins_out_100 udp&lt;BR /&gt;ip inspect name sdm_ins_out_100 ftp&lt;BR /&gt;ip inspect name sdm_ins_out_100 http&lt;BR /&gt;ip inspect name sdm_ins_out_100 pop3&lt;BR /&gt;interface Null0&lt;BR /&gt;interface FastEthernet0/0&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt; ip inspect sdm_ins_out_100 out&lt;BR /&gt;interface FastEthernet0/0/0&lt;BR /&gt;interface FastEthernet0/0/1&lt;BR /&gt;interface FastEthernet0/0/2&lt;BR /&gt;interface FastEthernet0/0/3&lt;BR /&gt;interface ATM0/2/0&lt;BR /&gt;interface ATM0/2/0.1 point-to-point&lt;BR /&gt;interface BRI0/2/0&lt;BR /&gt;interface ATM0/3/0&lt;BR /&gt;interface BRI0/3/0&lt;BR /&gt;interface Vlan1&lt;BR /&gt;interface Dialer1&lt;BR /&gt;ip nat inside source static tcp 192.168.16.2 1723 interface FastEthernet0/1 1723&lt;BR /&gt;ip nat inside source static tcp 192.168.16.2 47 interface FastEthernet0/1 47&lt;BR /&gt;ip nat inside source static udp 172.16.1.11 3101 interface FastEthernet0/1 3101&lt;BR /&gt;ip nat inside source static tcp 192.168.16.2 1701 interface FastEthernet0/1 1701&lt;BR /&gt;ip nat inside source static tcp 192.168.16.2 51 interface FastEthernet0/1 51&lt;BR /&gt;ip nat inside source static tcp 172.16.1.21 18080 interface FastEthernet0/1 18080&lt;BR /&gt;ip nat inside source static tcp 172.16.1.15 8001 interface FastEthernet0/1 8001&lt;BR /&gt;ip nat inside source static tcp 172.16.1.3 443 interface FastEthernet0/1 443&lt;BR /&gt;ip nat inside source static tcp 172.16.1.3 80 interface FastEthernet0/1 80&lt;BR /&gt;ip nat inside source static tcp 172.16.1.15 21 interface FastEthernet0/1 21&lt;BR /&gt;ip nat inside source static tcp 172.16.1.15 20 interface FastEthernet0/1 20&lt;BR /&gt;ip nat inside source static tcp 172.16.1.15 8002 interface FastEthernet0/1 8002&lt;BR /&gt;ip nat inside source static tcp 172.16.1.21 25 interface FastEthernet0/1 25&lt;BR /&gt;ip nat inside source static tcp 172.16.1.24 8080 interface FastEthernet0/1 8080&lt;BR /&gt;ip nat inside source route-map SDM_RMAP_1 interface FastEthernet0/1 overload&lt;BR /&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and I would insert the following settings&lt;/P&gt;&lt;P&gt;conf t&lt;BR /&gt;ip inspect name TEST http urlfilter&lt;BR /&gt;ip urlfilter allow-mode on&lt;BR /&gt;ip urlfilter exclusive-domain deny &lt;A href="http://www.dom1.de"&gt;www.dom1.de&lt;/A&gt;&lt;BR /&gt;ip urlfilter exclusive-domain deny &lt;A href="http://www.dom2.de"&gt;www.dom2.de&lt;/A&gt;&lt;BR /&gt;ip urlfilter exclusive-domain deny &lt;A href="http://www.dom3.de"&gt;www.dom3.de&lt;/A&gt;&lt;BR /&gt;ip urlfilter exclusive-domain deny &lt;A href="http://www.dom4.de"&gt;www.dom4.de&lt;/A&gt;&lt;BR /&gt;ip urlfilter exclusive-domain deny &lt;A href="http://www.dom5.de"&gt;www.dom5.de&lt;/A&gt;&lt;BR /&gt;ip urlfilter exclusive-domain deny *.dom1.de&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; is ist possible to usew wildcards?&lt;BR /&gt;ip urlfilter exclusive-domain deny *.dom2.de&lt;BR /&gt;ip urlfilter exclusive-domain deny *.dom3.de&lt;BR /&gt;ip urlfilter audit-trail&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt;ip inspect TEST out&lt;BR /&gt;end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jun 2010 10:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495619#M708814</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-06-15T10:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495620#M708815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you already have some firewall configured there: FW, sdm_ins_in_100 and sdm_ins_out_100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only interface FastEthernet0/1 has sdm_ins_out_100 configured, so the others are just not in use. If you add that config above, you remove the firewall sdm_ins_out_100 and configure TEST firewall only instead.&lt;/P&gt;&lt;P&gt;With that said I'm not sure what this breaks your remote session, but you probably have an ACL configured in FastEthernet0/1 that denies incoming traffic and since you don't inspect udp and tcp with TEST, you never open a whole to let the returning traffic crossing back your router and the packets are dropped in that ACL. So, in a short what you should have is integrate the urlfiltering to the already existing firewall:&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip inspect name sdm_ins_out_100 tcp&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip inspect name sdm_ins_out_100 udp&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip inspect name sdm_ins_out_100 ftp&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip inspect name sdm_ins_out_100 http&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip inspect name sdm_ins_out_100 pop3&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip inspect name sdm_ins_out_100 http urlfilter&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter allow-mode on&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter exclusive-domain deny &lt;A href="https://community.cisco.com/www.dom1.de" target="_blank"&gt;www.dom1.de&lt;/A&gt; ! Those three lines will be &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter exclusive-domain deny &lt;A href="https://community.cisco.com/www.dom2.de" target="_blank"&gt;www.dom2.de&lt;/A&gt; ! useless with the ones &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter exclusive-domain deny &lt;A href="https://community.cisco.com/www.dom3.de" target="_blank"&gt;www.dom3.de&lt;/A&gt; ! at the bottom&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter exclusive-domain deny www.dom4.de&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter exclusive-domain deny www.dom5.de&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter exclusive-domain deny .dom1.de&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter exclusive-domain deny .dom2.de&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter exclusive-domain deny .dom3.de&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip urlfilter audit-trail&amp;nbsp;&amp;nbsp;&amp;nbsp; ! &amp;lt;------ if you want to see logs of connections made only&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;interface FastEthernet0/1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp; ip inspect sdm_ins_out_100 out&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;That should allow the returning traffic in the (supposed configured) ACL on fast 0/1 for tcp, udp, ftp, http and pop3 - and that will reset the connection&amp;nbsp; and drop the outgoing packet if we try to access any www.domx.de.&lt;/DIV&gt;&lt;DIV&gt;And I don't know if you can use wildcards like &lt;SPAN style="font-family: 'courier new', courier;"&gt;*.dom1.de&lt;/SPAN&gt; but I have seen config with just &lt;SPAN style="font-family: 'courier new', courier;"&gt;.dom1.de&lt;/SPAN&gt; that should work instead.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jun 2010 15:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495620#M708815</guid>
      <dc:creator>Raphael Wouters</dc:creator>
      <dc:date>2010-06-15T15:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495621#M708816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raphael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you very muuch for your Help - this work!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One Question again:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to forward the blokes sites to a "access denied" side?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jun 2010 07:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495621#M708816</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-06-16T07:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: bock some urls?</title>
      <link>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495622#M708817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm glad this worked &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm afraid don't find the way to change the "blocked" page displayed with cbac, so I don't think it's possible... Maybe someone else on the forum can answer this for sure?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a nice day!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jun 2010 08:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bock-some-urls/m-p/1495622#M708817</guid>
      <dc:creator>Raphael Wouters</dc:creator>
      <dc:date>2010-06-16T08:10:40Z</dc:date>
    </item>
  </channel>
</rss>

