<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA SSM Module inspecting and blocking Internet Radio in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701148#M87512</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will give it a try, I didn't realize it used a  .ram suffix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Feb 2007 02:32:15 GMT</pubDate>
    <dc:creator>bjames</dc:creator>
    <dc:date>2007-02-22T02:32:15Z</dc:date>
    <item>
      <title>ASA SSM Module inspecting and blocking Internet Radio</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701146#M87507</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am implementing ASA's with SSM modules and I wanted confirmation that they can inspect http and block embedded traffic such as Internet Radio from being tunnelled through HTTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Cisco documentation hints at this, but I would like confirmation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will be implementing WebSense, but I was hoping the SSM modules would be a good temporary solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:28:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701146#M87507</guid>
      <dc:creator>bjames</dc:creator>
      <dc:date>2019-03-10T10:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA SSM Module inspecting and blocking Internet Radio</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701147#M87510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create a signature that uses the service http engine and a request regex = .ram, in monitoring -&amp;gt; events. As a action you can either choose "block attacker inline" which blocks user completely or better choose "TCP reset" option.&lt;/P&gt;&lt;P&gt;For Creating Custom Signatures follow the link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dmsigwiz.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dmsigwiz.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2007 19:55:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701147#M87510</guid>
      <dc:creator>gmarogi</dc:creator>
      <dc:date>2007-02-21T19:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA SSM Module inspecting and blocking Internet Radio</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701148#M87512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will give it a try, I didn't realize it used a  .ram suffix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 02:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701148#M87512</guid>
      <dc:creator>bjames</dc:creator>
      <dc:date>2007-02-22T02:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA SSM Module inspecting and blocking Internet Radio</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701149#M87513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using AIP-SSM (Intrusion Prevention) or CSC-SSM (Content Security)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2007 04:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701149#M87513</guid>
      <dc:creator>Andrew Ossipov</dc:creator>
      <dc:date>2007-02-23T04:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA SSM Module inspecting and blocking Internet Radio</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701150#M87515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IPS - SSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried filtering on REGX, but it will get every hit of .ram, so it's not too accurate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2007 22:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701150#M87515</guid>
      <dc:creator>bjames</dc:creator>
      <dc:date>2007-02-24T22:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA SSM Module inspecting and blocking Internet Radio</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701151#M87517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The AIP-SSM module is not designed for content filtering. You should probably try CSC-SSM for that, but you can also use Modular Policy Framework (MPF) on the ASA itself to accomplish the task:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/mpc.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/mpc.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's even simpler through ASDM, where you have some pre-defined maps that allow you to block streaming audio/video over HTTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Feb 2007 06:55:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701151#M87517</guid>
      <dc:creator>Andrew Ossipov</dc:creator>
      <dc:date>2007-02-25T06:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA SSM Module inspecting and blocking Internet Radio</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701152#M87518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, that's kind of what I figured. We want the IPS so we will stay with these modules, and use Websense for the filtering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My understanding of the SSM module is it provide much more inspection capabilities that the MPF inspects (it will do them all but provides more in-depth control)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Feb 2007 14:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-module-inspecting-and-blocking-internet-radio/m-p/701152#M87518</guid>
      <dc:creator>bjames</dc:creator>
      <dc:date>2007-02-25T14:34:39Z</dc:date>
    </item>
  </channel>
</rss>

