<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic URL-Filtering Smartfilter and HTTPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/url-filtering-smartfilter-and-https/m-p/1386235#M776997</link>
    <description>&lt;P&gt;Ok....hopefully someone out there can assist me. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an dual failover two ASA 5520 scenario that we are using for firewall purposes.&amp;nbsp; I have the URL filtering setup on these ASA's which are currently filtering http traffic without any problems.&amp;nbsp; However, when it comes to HTTPS....that's a whole other story.&amp;nbsp;&amp;nbsp; For some reason I can't get the ASA to send HTTPS traffic to the smartfilter server.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA version = 8.2(1)&lt;/P&gt;&lt;P&gt;Smartfilter version = 4.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Initially before starting this endeavor, we were on a cisco pix failover scenario using version 7.1.&amp;nbsp;&amp;nbsp; I had contacted TAC and they explained that we had to upgrade in order to resolve this problem.&amp;nbsp;&amp;nbsp; Therefore, I removed the pix's completely and put in the ASA's with 8.2(1) on them thinking this would fix the problem.&amp;nbsp;&amp;nbsp; Nope!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also contacted Mcafee, new owner of Secure Computing which owns Smartfilter, and they advised that version 4.1.1 supports https filtering and it has to be something with the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upon further investigation I did a 'show url-server stat' and noticed that i'm not sending any https requests to the filter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*******************************************************************************&lt;/P&gt;&lt;P&gt;Global Statistics:&lt;BR /&gt;--------------------&lt;BR /&gt;URLs total/allowed/denied&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 968201/904693/63508&lt;BR /&gt;URLs allowed by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/904693&lt;BR /&gt;URLs denied by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/63508&lt;BR /&gt;HTTPSs total/allowed/denied&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0/0&lt;BR /&gt;HTTPSs allowed by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&lt;BR /&gt;HTTPSs denied by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&lt;BR /&gt;FTPs total/allowed/denied&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0/0&lt;BR /&gt;FTPs allowed by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&lt;BR /&gt;FTPs denied by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&lt;BR /&gt;Requests dropped&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Server timeouts/retries&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/37&lt;BR /&gt;Processed rate average 60s/300s&amp;nbsp;&amp;nbsp; 36/31 requests/second&lt;BR /&gt;Denied rate average 60s/300s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2/2 requests/second&lt;/P&gt;&lt;P&gt;**********************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the commands i have in my config that relate to the URL filtering setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;url-server (inside) vendor smartfilter host xx.xxx.xxx.xxx port 4005 timeout 30 protocol UDP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow&lt;BR /&gt;filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It just doesnt seem as if my https traffic is making it to my smartfiliter.&amp;nbsp;&amp;nbsp; If anyone has any ideas, your help will be very VERY much appreciated.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:48:31 GMT</pubDate>
    <dc:creator>jonesl1</dc:creator>
    <dc:date>2019-03-11T16:48:31Z</dc:date>
    <item>
      <title>URL-Filtering Smartfilter and HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-smartfilter-and-https/m-p/1386235#M776997</link>
      <description>&lt;P&gt;Ok....hopefully someone out there can assist me. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an dual failover two ASA 5520 scenario that we are using for firewall purposes.&amp;nbsp; I have the URL filtering setup on these ASA's which are currently filtering http traffic without any problems.&amp;nbsp; However, when it comes to HTTPS....that's a whole other story.&amp;nbsp;&amp;nbsp; For some reason I can't get the ASA to send HTTPS traffic to the smartfilter server.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA version = 8.2(1)&lt;/P&gt;&lt;P&gt;Smartfilter version = 4.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Initially before starting this endeavor, we were on a cisco pix failover scenario using version 7.1.&amp;nbsp;&amp;nbsp; I had contacted TAC and they explained that we had to upgrade in order to resolve this problem.&amp;nbsp;&amp;nbsp; Therefore, I removed the pix's completely and put in the ASA's with 8.2(1) on them thinking this would fix the problem.&amp;nbsp;&amp;nbsp; Nope!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also contacted Mcafee, new owner of Secure Computing which owns Smartfilter, and they advised that version 4.1.1 supports https filtering and it has to be something with the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upon further investigation I did a 'show url-server stat' and noticed that i'm not sending any https requests to the filter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*******************************************************************************&lt;/P&gt;&lt;P&gt;Global Statistics:&lt;BR /&gt;--------------------&lt;BR /&gt;URLs total/allowed/denied&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 968201/904693/63508&lt;BR /&gt;URLs allowed by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/904693&lt;BR /&gt;URLs denied by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/63508&lt;BR /&gt;HTTPSs total/allowed/denied&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0/0&lt;BR /&gt;HTTPSs allowed by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&lt;BR /&gt;HTTPSs denied by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&lt;BR /&gt;FTPs total/allowed/denied&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0/0&lt;BR /&gt;FTPs allowed by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&lt;BR /&gt;FTPs denied by cache/server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&lt;BR /&gt;Requests dropped&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Server timeouts/retries&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/37&lt;BR /&gt;Processed rate average 60s/300s&amp;nbsp;&amp;nbsp; 36/31 requests/second&lt;BR /&gt;Denied rate average 60s/300s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2/2 requests/second&lt;/P&gt;&lt;P&gt;**********************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the commands i have in my config that relate to the URL filtering setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;url-server (inside) vendor smartfilter host xx.xxx.xxx.xxx port 4005 timeout 30 protocol UDP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow&lt;BR /&gt;filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It just doesnt seem as if my https traffic is making it to my smartfiliter.&amp;nbsp;&amp;nbsp; If anyone has any ideas, your help will be very VERY much appreciated.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-smartfilter-and-https/m-p/1386235#M776997</guid>
      <dc:creator>jonesl1</dc:creator>
      <dc:date>2019-03-11T16:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: URL-Filtering Smartfilter and HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/url-filtering-smartfilter-and-https/m-p/1386236#M776998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls. follow this link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/ef.html#wp1970383"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/ef.html#wp1970383&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this command below instead of what you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;filter https 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 18:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-filtering-smartfilter-and-https/m-p/1386236#M776998</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-14T18:43:24Z</dc:date>
    </item>
  </channel>
</rss>

