10-29-2017 11:56 PM - edited 02-21-2020 06:35 AM
Hi Experts,
Is it possible to block only certain Internet URLs using their IP address and permit all other(ANY) Internet URLs using ASA Firewall. Can you help me with the ACL statements if possible?
Please comment
Thanks
Sreeraj
10-30-2017 12:57 AM
you resolve (ping or nslookip) those URL to their IP addresses, then just apply it a permitted destination in the ACL policies. That basically the way.
But It is also a very unreliable way as many URL (actually FQDN) are hosted/fronted by CDN caches in the internet which mean they use quite a number of different ip addresses (of different subnet blocks). Many of them also quite dynamic (change frequently) in natural so trying to manually tracked it is not reliable mostly. The right way to block destination by URL should be performed on your web security gateway (i.e forward we proxy) instead.
10-30-2017 02:04 AM
10-30-2017 03:39 AM
You could better achieve that with the URL-filtering capabilities on a NGFW like Cisco Firepower or Meraki MX.
You can try FQDN-based ACLs:
10-30-2017 10:44 PM
Thanks Karsten Iwen, Sure I will explore.
I did this(ATTACHED IN THE SCREENSHOT ATTACHED) as a temporary work around, hope this is valid.
Please comment your expert inputs.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide