cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
558
Views
0
Helpful
6
Replies

ASA with CSC Module - does it not show restricted sites attempted?

johnaceti
Level 1
Level 1

Thanks for taking a look at this,

We recently installed a Cisco ASA-5510 with 8.0(4) with a  CSC module.

Although it does in fact block users from restricted sites it does not tell him in the CSC Events what site it was that got blocked from the user.

Does anyone know if there is any workaround for that? If a user was restricted they need to know what site was attempted.

6 Replies 6

Maykol Rojas
Cisco Employee
Cisco Employee

Hi,

If you go to, logs, query and you select, url blocking/filtering, you should see the attempts there.

Mike

Mike

thank you!

johnaceti
Level 1
Level 1

Thanks, and yes we now see the IP's but is there a way to show the actual URL that was attempted?

Hey,

I dont know if you got what you were looking for. Below link gives list of syslogs on CSC SSM:

http://www.cisco.com/en/US/docs/security/csc/csc66/administration/guide/cscappa.html#wp1102109

As you can see there are a bunch og logs produced along with the URL that was blocked. Hope this helps!!

Regards,

Prapanch

Message was edited by: Prapanch Ramamoorthy

Not exactly.

The customer would like to know the URL that was attempted.

This is what he sees

is-url-filtering: 2006/01/01 17:10:59|forbidden.com/|10.2.3.4|Company Prohibited Sites|

This is what he prefers so see so it is similar to his previous content filter that he replaced.

is-url-filtering: 2006/01/01 17:10:59|forbidden.com/|http://girls.com|Company Prohibited Sites|

Disregard my last , we got it, thanks!

Review Cisco Networking for a $25 gift card