04-20-2016 10:54 AM - edited 03-12-2019 12:38 AM
We have a group of computers denied access outside our network with an access rule setup on our ASA5515. This rule keeps all computer within a certain subnet from having internet access outside the firewall. We want to setup 1 computer to have access the weather information at www.noaa.gov. ; I do not have an IP address that will access this website.
Is there a way to set an access rule to use the website name instead of the ip address?
Thanks in advance.
Solved! Go to Solution.
04-20-2016 08:33 PM
You don't need to resort to regex. You can use a FQDN in an ACL as long as you have defined a working DNS server for the ASA to use.
We usually don't do it or recommend it since we generally don't want to slow down the ASA by having it do DNS lookup but it should work OK for a single host.
Here's the reference from the configuration guide:
http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html#ID-2069-00000206
04-20-2016 04:24 PM
You can accomplish this with creating an inspection policy for HTTP and some regex. For more info, check the following link:
Thank you for rating helpful posts!
04-20-2016 08:33 PM
You don't need to resort to regex. You can use a FQDN in an ACL as long as you have defined a working DNS server for the ASA to use.
We usually don't do it or recommend it since we generally don't want to slow down the ASA by having it do DNS lookup but it should work OK for a single host.
Here's the reference from the configuration guide:
http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html#ID-2069-00000206
04-21-2016 04:57 PM
Heeey now, no need to bash my regex solution. Some of us like regex :)
Btw, I think we can all agree that getting URL filtering with FirePOWER would be a much cleaner solution and not that expensive!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide