07-09-2015 03:26 AM - edited 03-11-2019 11:14 PM
How do I blacklist and enable blocking of external sites I do not want people to visit from my network using ASA5545 device
07-09-2015 03:53 AM
I also need to block some https:// traffic
07-09-2015 07:02 AM
Hi,
With only the ASA device and no extra modules , you can only block HTTP url using the REGEX:-
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/100535-asa-8x-regex-config.html
Other than this , you can try to block HTTPS websites using the REGEX on the DNS queries through the ASA device.
I would recommend using an external module feature on the ASA device for this and as per the ASA model , Sourcefire should be the way to go:-
http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html
Thanks and Regards,
Vibhor Amrodia
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide