<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to block http://X.X.X.X/login.aspx from being accessed b in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403402#M760181</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kusankar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, we do not have CSC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, after I removed the second regular expression and left only login2 (login.aspx), it started working. Now, we can access to the web site at normal time and noone can access to &lt;A href="http://X.X.X.X/login.aspx"&gt;http://X.X.X.X/login.aspx&lt;/A&gt; . There is one thing though, when people tries to access &lt;A href="http://X.X.X.X/login.aspx"&gt;http://X.X.X.X/login.aspx&lt;/A&gt; the pc waits for 5-10 minutes before it fails to connect. Is there any way to decrease the time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Semih&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Feb 2010 03:16:26 GMT</pubDate>
    <dc:creator>Network Administrator</dc:creator>
    <dc:date>2010-02-17T03:16:26Z</dc:date>
    <item>
      <title>How to block http://X.X.X.X/login.aspx from being accessed by internet?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403397#M760158</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ASA 5510 (8.0.2), ASDM 6.1 and ASA-SSM-10 6.1. We have a web site located at DMZ with a Public IP address. It is accessible from Internet via the public IP address. While keeping web site access enabled, I need to block access to &lt;A href="http://X.X.X.X/Login.aspx" target="_blank"&gt;http://X.X.X.X/Login.aspx&lt;/A&gt; from Public IP addresses,ie, Internet. We still need to access to this link from inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I tried to create regular expressions with \x.x.x.x AND \X.X.X.\login.aspx&lt;/P&gt;&lt;P&gt;2. I created a regular expression class and allocated these two expressions to the class.&lt;/P&gt;&lt;P&gt;3. Then I created an http class map&amp;nbsp; with Criterion "Request URI" and the Value Regular Expression Class that I have created above (2) for http inspection policy.&lt;/P&gt;&lt;P&gt;4. Then I created an HTTP Inspect map and added inspection for the http class map that I have created(3) with the action "Reset" and log "Enable".&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Then I added a new service policy to outside interface.&lt;/P&gt;&lt;P&gt;6. Match criteria "source and Destination IP..."&lt;/P&gt;&lt;P&gt;7. Source : Any, Destination : X.X.X.X, service: tcp/http and enabled rule&lt;/P&gt;&lt;P&gt;8. At Protocol inspection, checked "HTTP" and clicked on Configuration&lt;/P&gt;&lt;P&gt;9. "Select a HTTP inspect map for the fine control..." and choose the inspection policy created above (3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, aftyer this config change, we were still able to access to &lt;A href="http://X.X.X.X/Login.aspx" target="_blank"&gt;http://X.X.X.X/Login.aspx&lt;/A&gt; from bopth inside and outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any suggestions...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Semih&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403397#M760158</guid>
      <dc:creator>Network Administrator</dc:creator>
      <dc:date>2019-03-11T17:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to block http://X.X.X.X/login.aspx from being accessed b</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403398#M760161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;check this link out:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1268"&gt;https://supportforums.cisco.com/docs/DOC-1268#Block_specific_urls&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this what you configured and it does not work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Feb 2010 02:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403398#M760161</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-02-17T02:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to block http://X.X.X.X/login.aspx from being accessed b</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403399#M760165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kusankar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I followed that link's instructions for "Block spefific uris". But with the following changes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I used case insensitive regular expressions to cover login or login.aspx:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regex login2 "/[Ll][Oo][Gg][Ii][Nn].[Aa][Ss][Pp][Xx]"&lt;BR /&gt;regex login "/[Ll][Oo][Gg][Ii][Nn]"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. I did not apply it to Global policy. Since I wanted to block only incoming requests from outside to our dmz, I applied it to outside interface and outside policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I can not even access to http:/X.X.X.X web site from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Semih&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Feb 2010 02:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403399#M760165</guid>
      <dc:creator>Network Administrator</dc:creator>
      <dc:date>2010-02-17T02:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to block http://X.X.X.X/login.aspx from being accessed b</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403400#M760170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kusankar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just an update, it reached to &lt;A href="http://X.X.X.X"&gt;http://X.X.X.X&lt;/A&gt; but extremely slow. It takes around 5 minutes to load the web site. It also blocks login.aspx. But if I remove the inspection, it loads in 10 seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Semih&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Feb 2010 02:29:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403400#M760170</guid>
      <dc:creator>Network Administrator</dc:creator>
      <dc:date>2010-02-17T02:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to block http://X.X.X.X/login.aspx from being accessed b</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403401#M760175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you also have a CSC module?&lt;/P&gt;&lt;P&gt;Any errors on the interfaces? sh int | i errors&lt;/P&gt;&lt;P&gt;adding http inspection required packets to arrive in order on the ASA. If you recieve large amount of out of order packets then this is going to add latency.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Feb 2010 02:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403401#M760175</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-02-17T02:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to block http://X.X.X.X/login.aspx from being accessed b</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403402#M760181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kusankar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, we do not have CSC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, after I removed the second regular expression and left only login2 (login.aspx), it started working. Now, we can access to the web site at normal time and noone can access to &lt;A href="http://X.X.X.X/login.aspx"&gt;http://X.X.X.X/login.aspx&lt;/A&gt; . There is one thing though, when people tries to access &lt;A href="http://X.X.X.X/login.aspx"&gt;http://X.X.X.X/login.aspx&lt;/A&gt; the pc waits for 5-10 minutes before it fails to connect. Is there any way to decrease the time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Semih&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Feb 2010 03:16:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403402#M760181</guid>
      <dc:creator>Network Administrator</dc:creator>
      <dc:date>2010-02-17T03:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to block http://X.X.X.X/login.aspx from being accessed b</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403403#M760187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can change the action from "drop-connection" to reset. Then the browser will know right away that he was denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Feb 2010 16:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403403#M760187</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-17T16:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to block http://X.X.X.X/login.aspx from being accessed b</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403404#M760189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks everone for the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already used Kusankar's link for this. But it started working only after I used one parameter rather than 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the delay in rejecting the access, I changed the action to reset rather than drop connection as recomended by pkampana; it did not do any changes. Currently, web site is accessible and /login.aspx is blocked. Therefore I will leave it as is for now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Semih&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Feb 2010 01:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-http-x-x-x-x-login-aspx-from-being-accessed-by/m-p/1403404#M760189</guid>
      <dc:creator>Network Administrator</dc:creator>
      <dc:date>2010-02-18T01:11:23Z</dc:date>
    </item>
  </channel>
</rss>

