cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
645
Views
0
Helpful
2
Replies

Allowing some URL while restricting the Country

charles_nana
Level 1
Level 1

Hi,

I have a unique situation with my ASA5516X with Firepower 6.22. I need to block all the traffic from specific Geo Location while allowing only few know websites from same Geo Location.

To achieve that I created a URL list under

Objects --> Security Intelligence --> URL list and feeds.

Then I added newly created list to the whitelists under

Access Control Policies --> Security Intelligence --> URLs Tab.

But still I cannot access those web sites. Am I doing it correct.

 

Thanks

Charles

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

If the blocked Geo is in your Security Intelligence list it will deny the traffic to the subset that you have allowed in the ACP rule due to order of operations since SI is always evaluated before ACP rules.

Hi Marvin,

Thanks for your reply. Is there any way other way to do this ? Which will allow me to access identified few sites from a Geo location which is blocked ?

Thanks

Charles

Review Cisco Networking for a $25 gift card