cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1621
Views
0
Helpful
5
Replies

ASA webfilter using regex

Hi all,

I have a ASA 5510, it does webfilter using regular expression. (http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080940e04.shtml)

I block "\.facebook\.com" and it was successfull. But somehow other users is using https to access to FB.

Any ideas on how do i filter HTTPS?

1 Accepted Solution

Accepted Solutions

yes, to filter based on fqdn you need at least version 8.4(2). But be aware of the increased memory-requirements starting with version 8.3: http://www.cisco.com/en/US/docs/security/asa/asa83/release/notes/asarn83.html#wp454755

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

View solution in original post

5 Replies 5

lcambron
Level 9
Level 9

Im afraid this is not possible with the ASA, since the connection is encrypted, the ASA cannot inspect it.

You would need a different solution like websense.

Regards,

Felipe.

If you are runing 8.4, then you can filter that in your ACL based on FQDN: https://supportforums.cisco.com/docs/DOC-17014

Sent from Cisco Technical Support iPad App

--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

currently I'm using ASA Version 8.0(3). Does it mean i need to upgrade the firmware to 8.4 then I able to perform the https filter as you describe above??

yes, to filter based on fqdn you need at least version 8.4(2). But be aware of the increased memory-requirements starting with version 8.3: http://www.cisco.com/en/US/docs/security/asa/asa83/release/notes/asarn83.html#wp454755

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

OK tq,

I will try and see the result.

Review Cisco Networking for a $25 gift card