<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restriction of Web Sites in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/restriction-of-web-sites/m-p/1205142#M835662</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you can only block certain websites, rather than allow certain websites, therefore regexp is no use to you really.&lt;/P&gt;&lt;P&gt;REGEXP config example here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940c5a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940c5a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only other option (and it costs) is to purchase a CSC-SSM module. More info here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/ps6823/product_data_sheet0900aecd80402e4f_ps6120_Products_Data_Sheet.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/ps6823/product_data_sheet0900aecd80402e4f_ps6120_Products_Data_Sheet.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 May 2009 13:44:58 GMT</pubDate>
    <dc:creator>handsy</dc:creator>
    <dc:date>2009-05-15T13:44:58Z</dc:date>
    <item>
      <title>Restriction of Web Sites</title>
      <link>https://community.cisco.com/t5/network-security/restriction-of-web-sites/m-p/1205141#M835660</link>
      <description>&lt;P&gt;Greetings, All.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to a *very* stringent security policy, the users behind a specific ASA 5505 (v 8.04) will only be allowed to access a limited number of web sites. For simplicities sake, let's just say they can only access &lt;A class="jive-link-custom" href="http://www.espn.com" target="_blank"&gt;www.espn.com&lt;/A&gt; and &lt;A class="jive-link-custom" href="http://www.yahoo.com," target="_blank"&gt;www.yahoo.com,&lt;/A&gt; and nothing else. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've monkeyed with the configs a bit and haven't had any luck. I've attached the config with which I've tried to make this happen. Perhaps I'm close? Is my access list jacked? With this config, everything is blocked...including espn and yahoo. Not exactly what I want. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL filtering is not an option as WebSense will be too costly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do know that you can keep users from visiting specific sites (gambling, porn, etc;), but what if you want to keep the users from visiting any site except maybe 1 or 2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restriction-of-web-sites/m-p/1205141#M835660</guid>
      <dc:creator>cavemanbobby</dc:creator>
      <dc:date>2019-03-11T15:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: Restriction of Web Sites</title>
      <link>https://community.cisco.com/t5/network-security/restriction-of-web-sites/m-p/1205142#M835662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you can only block certain websites, rather than allow certain websites, therefore regexp is no use to you really.&lt;/P&gt;&lt;P&gt;REGEXP config example here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940c5a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940c5a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only other option (and it costs) is to purchase a CSC-SSM module. More info here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/ps6823/product_data_sheet0900aecd80402e4f_ps6120_Products_Data_Sheet.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/ps6823/product_data_sheet0900aecd80402e4f_ps6120_Products_Data_Sheet.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 13:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restriction-of-web-sites/m-p/1205142#M835662</guid>
      <dc:creator>handsy</dc:creator>
      <dc:date>2009-05-15T13:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Restriction of Web Sites</title>
      <link>https://community.cisco.com/t5/network-security/restriction-of-web-sites/m-p/1205143#M835665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can limit where people go with regex and class maps. I have a handful of users that are only allowed to go to certain sites, and here's what I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create your acl:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list RESTRICTED permit ip host 192.168.1.5 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Match that ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map RESTRICTED&lt;/P&gt;&lt;P&gt;match access-list RESTRICTED&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create your regex:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regex espn "\.espn\.com"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create your regex class-map:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type regex match-any Internet_Allowed&lt;/P&gt;&lt;P&gt;match regex espn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inspect the regex class map, but only allow what DOESN'T match:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all INTERNET_RESTRICTED&lt;/P&gt;&lt;P&gt; match not request header host regex class Internet_Allowed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a policy map to perform actions on above:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect http RESTRICTED_INTERNET&lt;/P&gt;&lt;P&gt;class INTERNET_RESTRICTED&lt;/P&gt;&lt;P&gt;    reset log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(The reset above will reset any connection that DOESN'T match your regex. It allows only espn.com.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then create a policy to apply to the inside interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map INSIDE&lt;/P&gt;&lt;P&gt;class RESTRICTED&lt;/P&gt;&lt;P&gt;inspect http RESTRICTED_INTERNET&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(The class above matches the acl for your hosts, and the it applies the other policy map RESTRICTED_INTERNET to scan against your acl.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2009 14:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/restriction-of-web-sites/m-p/1205143#M835665</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-15T14:46:43Z</dc:date>
    </item>
  </channel>
</rss>

