<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: allow 1 url while blocking others in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714226#M86743</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;bump...any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 May 2007 18:53:40 GMT</pubDate>
    <dc:creator>art_henry</dc:creator>
    <dc:date>2007-05-21T18:53:40Z</dc:date>
    <item>
      <title>allow 1 url while blocking others</title>
      <link>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714225#M86742</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running an ASA w/AIP.  What I would like to do is block all url request for .php except for 1 url.  The engine being used for the custom signature is service-http.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried ([^(allow.site)][A-Za-z][0-9])*\x2E([Pp\x50\x70][Hh\x48\x68][Pp\x50\x70])&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After configuring this custom signature the IPS complains that all signatures might not fire and signatures should be retired.  I've tried to reduce the signatures but the custom signature is still to demanding.  My question is, are there any other suggestions as to how this can be achieved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:36:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714225#M86742</guid>
      <dc:creator>art_henry</dc:creator>
      <dc:date>2019-03-10T10:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: allow 1 url while blocking others</title>
      <link>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714226#M86743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;bump...any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2007 18:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714226#M86743</guid>
      <dc:creator>art_henry</dc:creator>
      <dc:date>2007-05-21T18:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: allow 1 url while blocking others</title>
      <link>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714227#M86744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should have the latest signature version installed, as there has been some modification that helped in the memory side, compared to some older signature version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think something like this should do (have to define allow.site more).&lt;/P&gt;&lt;P&gt;[^(allow.site)][.][Pp][Hh][Pp]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if the port the traffic is expected on is a port listed on WEBPORTS under signature variable in IDM, define the port as #WEBPORTS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, please clarify what is the url you want to allow, and a sample of what you do not want to allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2007 03:48:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714227#M86744</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2007-05-22T03:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: allow 1 url while blocking others</title>
      <link>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714228#M86745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;edadios,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the suggestions.  I did upgrade from signatures 280 to 287.  The traffic is a webport, in fact it is a custom variable as the amount of ports configured in web ports weren't necessary.  I also followed your suggestion in trimming down the regular expresion.  Unfortunately I still get the resource warning "Warning: WARNING: Insufficient resources available to combine all currently acti&lt;/P&gt;&lt;P&gt;ve custom regexes. Some alerts will not fire. Consider retiring signatures until&lt;/P&gt;&lt;P&gt; this message no longer occurs."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2007 15:33:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714228#M86745</guid>
      <dc:creator>art_henry</dc:creator>
      <dc:date>2007-05-22T15:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: allow 1 url while blocking others</title>
      <link>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714229#M86746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From your statement &lt;/P&gt;&lt;P&gt;"in fact it is a custom variable as the amount of ports configured in web ports weren't necessary"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should still use the #WEBPORTS, and also remove the custom variable you have created if it is a subset of #WEBPORTS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have other custom signatures you have already created on the sensor, that could be adding to the issue with resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, I believe you already have a service request logged, I suggest you forward the information pertaining to this issue through that SR, so we could obtain from you further information about your ASA that could help in determining cause for your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would help to have the existing configuration of the sensor, and what the actual regular expression you are trying to add.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Providing a sample capture traffic of what you want to be allowed, and what you want the sensor to alarm on, by uploading it to the service request, we could help in writing the custom signature for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 00:47:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714229#M86746</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2007-05-23T00:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: allow 1 url while blocking others</title>
      <link>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714230#M86747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your comments.  The SR I have is not to address the intensity of the signature it is another issue, but I will pursue further with a SR.  Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 13:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-1-url-while-blocking-others/m-p/714230#M86747</guid>
      <dc:creator>art_henry</dc:creator>
      <dc:date>2007-05-23T13:53:02Z</dc:date>
    </item>
  </channel>
</rss>

