<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA as an http proxy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496847#M732747</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm what about the policy based routing option? Is their a router or L3 switch behind the ASA that could support policy based routing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Jul 2010 20:06:55 GMT</pubDate>
    <dc:creator>August Ritchie</dc:creator>
    <dc:date>2010-07-22T20:06:55Z</dc:date>
    <item>
      <title>ASA as an http proxy</title>
      <link>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496842#M732690</link>
      <description>&lt;P&gt;Does anyone know if the ASA can be configured to redirect ht&lt;/P&gt;&lt;P&gt;tp traffic to a Proxy Server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496842#M732690</guid>
      <dc:creator>davep</dc:creator>
      <dc:date>2019-03-11T18:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA as an http proxy</title>
      <link>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496843#M732700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as redirecting HTTP traffic you can redirect using url-filtering or wccp. URL filtering seem more like what you are wanting. It works with the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;LI&gt;&lt;/LI&gt;&lt;/P&gt;&lt;P&gt;Websense Enterprise—filters HTTP, HTTPS, and FTP. It is supported by PIX firewall version 5.3 and later.&lt;/P&gt;&lt;LI&gt;&lt;P&gt;Secure Computing SmartFilter, formerly known as N2H2—filters HTTP, HTTPS, FTP, and long URL filtering. It is supported by PIX firewall version 6.2 and later.&lt;/P&gt;&lt;/LI&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008088517b.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008088517b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WCCP redirection is for sending traffic to a caching engine which is more used for speeding up connections via caching.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1094445"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1094445&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 19:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496843#M732700</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-07-22T19:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA as an http proxy</title>
      <link>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496844#M732713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;August,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the response. Unfortunately, in this case it is a web filter like WebSense, but it is not one supported through the url-server command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, it is not a cache engine either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other options?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 19:44:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496844#M732713</guid>
      <dc:creator>davep</dc:creator>
      <dc:date>2010-07-22T19:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA as an http proxy</title>
      <link>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496845#M732720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, these are the only ways I know of for an ASA to redirect HTTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some alternative none ASA ways would be to use a router before the ASA to do policy-based routing for all HTTP traffic to a different next hop (I.E. filtering server). The ASA doesn't support Policy Based Routing, thats why it is not an option on the ASA. Or to run the filter transparently inline between the ASA and inside (I don't know to much about this feature).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 19:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496845#M732720</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-07-22T19:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA as an http proxy</title>
      <link>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496846#M732736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;August,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, thank you for the reply. Your last option (transparent between the internal network and the ASA) was my recommendation. However, the filter box can only use 1 nic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 20:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496846#M732736</guid>
      <dc:creator>davep</dc:creator>
      <dc:date>2010-07-22T20:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA as an http proxy</title>
      <link>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496847#M732747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm what about the policy based routing option? Is their a router or L3 switch behind the ASA that could support policy based routing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 20:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496847#M732747</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-07-22T20:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA as an http proxy</title>
      <link>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496848#M732753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If my memory serves me right, with the Websense platform you can go two ways...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 1) PIX/ASA integration using the url-server keyword.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; As you noted, this option is out... So lets roll on to.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 2) Span session based redirect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The other way Websense can work is by spanning your internet traffic to the monitorring port of the websense appliance. WHen configured as such, it watches the HTTP traffic similar to a promiscous IPS would. When it detects a web connection that should be blocked, it generates two RESET packets and sends one towards the HTTP client and one towrds the HTTP server. In this config you need to use the 'monitor session' keywords on an switch that the inside of the ASA connects to. You would then span that port (the one between the ASA inside interface and your switch) to the websense monitor port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is option 2 what our are looking for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Jul 2010 03:24:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-as-an-http-proxy/m-p/1496848#M732753</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-07-24T03:24:48Z</dc:date>
    </item>
  </channel>
</rss>

