cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2118
Views
5
Helpful
4
Replies

Blocking specific URL(using IP Address) with ASA Firewall Access list

sreeraj.murali
Level 3
Level 3

Hi Experts,

Is it possible to block only certain Internet URLs using their IP address and permit all other(ANY) Internet URLs using ASA Firewall. Can you help me with the ACL statements if possible?

 

Please comment

 

Thanks

Sreeraj

4 Replies 4

yongaik
Level 1
Level 1

you resolve (ping or nslookip) those URL to their IP addresses, then just apply it a permitted destination in the ACL policies. That basically the way.

 

But It is also a very unreliable way as many URL (actually FQDN) are hosted/fronted by CDN caches in the internet which mean they use quite a number of different ip addresses (of different subnet blocks). Many of them also quite dynamic (change frequently) in natural so trying to manually tracked it is not reliable mostly. The right way to block destination by URL should be performed on your web security gateway (i.e forward we proxy) instead.

Ok. Thanks for the comment. Agree with you, to add a permit statement for allowing specific URL.
however, if I want to deny access to certain URLS and permit to rest of all URLs, how can I achieve it. I am thinking the possibility of blocking access to Facebook, Youtube and streaming video websites, and allowing access to all other Internet URLs. Please help.

Thanks Karsten Iwen, Sure I will explore.

 

I did this(ATTACHED IN THE SCREENSHOT ATTACHED) as a temporary work around, hope this is valid.

 

Please comment your expert inputs.

 

 

Review Cisco Networking for a $25 gift card