cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4861
Views
0
Helpful
16
Replies

Cisco firewall not allowing ngrok.com

muqtaderrazvi
Level 1
Level 1

when I am visiting ngrok.com I am getting the error "Access to this destination is not allowed due to a possible malware threat"

what could be the issue?

ASA is blocking ngrok software too within the network.

16 Replies 16

Abheesh Kumar
VIP Alumni
VIP Alumni
Hi,
Are you using Cisco WSA, Its not blocked by ASA may be your proxy is denying this traffic.

HTH
Abheesh

no we are not using any proxy and wsa

balaji.bandi
Hall of Fame
Hall of Fame

as per the Talos site looks neutral, is the ASA with Firepower ?

 

https://www.talosintelligence.com/

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

no we are not using firepower.

this is why I am confused why ASA is blocking, moreover talcos is showing the website as neutral

we need more inforamtion about your setup, this error produce internally ? if so how is your traffic flow going outside, in the path from user pc to internet, there is some kind proxy or thread analysis running to get this.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

User PC----->Access Switch (2960)----->Core Switch (3850)----->ASA

 

There is no proxy and tread analysis

After ASA internet ?

is the error you see on browser ?

 

can you give us full screenshot, what IP address this sending this warning.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

yes, internet is after asa. 

we are seeing this error on browser. Attachment contains the screenshot of the browser.

Does your PC have Any Connect Client ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

No we don't have any connect. It is not just the one PC that is facing this problem, all PC in network is having same problem.

Ngrok site uses SSL and if you open the page with http it will be redirected to https. In your case some thing in between is blocking the page itself. Are you using Cisco umbrella..? Can you check nslookup from your PC whether it is resolving properly...?

Not using cisco umbrella 

Nslookup is fine giving same ip. check attachment

I think for now we are only guessing how your network, based on that we are suggesting. either you have some filters which is part of the network. Since we do not able to reproduce the isse you were mentioned.

 

who is your service ISP provider ? 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

my ISP is beam (from India)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card