cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2783
Views
0
Helpful
2
Replies

Firepower URL-blocking - how to see hosts?

cisco
Level 1
Level 1

Hi,

I am working with setting up a Firepower-system on a ASA5525X. I have enabled blocking of some URL-categories, this is working fine and I can see that a number of connections to forbiddel categories are stopped. But how can I drill this down and see what internal hosts are trying to access forbiddel URLs? Any standard reports or dashboards that gives this information?

Regards,

Thor-Egil

1 Accepted Solution

Accepted Solutions

Boris Uskov
Level 4
Level 4

Hello, what do you use for configuration of FirePOWER module? ASDM or FirePOWER Management Center (FMC)? In FMC you can get detailed information about every transaction in tab Analysis -> Connection -> Events. Please, see the attach.

But first, you need to configure logging in the Access Policies.

View solution in original post

2 Replies 2

Boris Uskov
Level 4
Level 4

Hello, what do you use for configuration of FirePOWER module? ASDM or FirePOWER Management Center (FMC)? In FMC you can get detailed information about every transaction in tab Analysis -> Connection -> Events. Please, see the attach.

But first, you need to configure logging in the Access Policies.

Thank you fpr your anwer, this was what I was looking for.

Br,

Thor-Egil

Review Cisco Networking products for a $25 gift card