11-30-2018 12:37 AM - edited 02-21-2020 08:31 AM
This is my policy table
My model is I configured on the FMC asa (Vmware) routing table network layer as pictured with the peplink device and at the same time configuring nat (i tried removing nat) but apparently the application like viber, outlook still works Even though there are internet policy rules
It seems that the deny policy of the asa firewall still has holes in the application department when I have tried quite a few ways but the application can still go out the internet but while the website was blocked
11-30-2018 12:43 AM - edited 11-30-2018 12:47 AM
Hi,
Your rule will match the source destination traffic, as you mentioned the destination IP's.
Create a rule with source IP and destination any, then select the URL which you would like to block.
Create another rule with source IP, destination any and then select the application category and choose the application you would like to block.
HTH
Abheesh
11-30-2018 01:07 AM - edited 11-30-2018 01:10 AM
Hi,
My intention is to want the ip address on the 2 visited sites and block all other applications .But it seems that asa does not understand, applications such as viber can still send messages while banned other sites.
I have created a rule block all below but it seems that I can not do my job
11-30-2018 01:16 AM
11-30-2018 01:26 AM
Yes, my wish is that
11-30-2018 01:34 AM
11-30-2018 05:47 PM
I have configured blocking policy like this and it does not understand blocking the application
11-30-2018 10:41 PM - edited 11-30-2018 10:41 PM
can you change the action to BLOCK WITH RESET and try.
HTH
Abheesh
11-30-2018 10:47 PM
11-30-2018 10:50 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide