08-24-2018 06:29 AM
Hi
We need to grant internet access to our jump stations, but only to limited sites.
The ideal way would be if the user could open a browser session, get redirected to ISE, enters the URL, ISE added this URL or IP address to FirePower or the ASA, and then the site can be accessed?
Today we are using the cut-through proxy on the ASA, users access a site, gets prompted for username and password, and then has access to everything. We would like to have the user add ACE's, to the "Jumpstation_internet_access" ACL. Then with a fixed frequency, our security team could audit the ACL.
If someone has a different solution, I'll be glad to hear it. Perhaps there are a more suitable way to deliver a reasonable experience for the users, without compromising security.
Solved! Go to Solution.
08-24-2018 09:10 AM - edited 08-24-2018 01:33 PM
It sounds like you want workflow to add URL/IP to ACE. I can't say for Firepower, but certainly not native function of ISE. Have you looked at WSA? ISE could move users to VLAN where users are forced to go through WSA, and WSA can lookup users that ISE can share. But, since WSA deals with URLs they may have feature for such workflow.
08-24-2018 09:06 AM
08-24-2018 09:10 AM - edited 08-24-2018 01:33 PM
It sounds like you want workflow to add URL/IP to ACE. I can't say for Firepower, but certainly not native function of ISE. Have you looked at WSA? ISE could move users to VLAN where users are forced to go through WSA, and WSA can lookup users that ISE can share. But, since WSA deals with URLs they may have feature for such workflow.
08-26-2018 11:02 PM
It might be that I'm shooting over the edge with a ISE/FP solution, trying to solve a relatively easy problem with alot of moving parts. I'll try with the ASA cut-through proxy again, and see if I'm able to optimize it somehow.
Thanks for your suggestions!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide