03-27-2015 01:32 AM - edited 03-12-2019 05:38 AM
Have asa5512x with firepower and 5.4 installed on device and defence centre is also 5.4
everything was working ok up until 2 days ago were the url filtering will stop blocking bad sites. in the connection event logs it does not show anymore
the url category or reputation on the specific website, it is blank. at the access control rule it show default action. it is as if the access control policy is not working at all. have seen previous question about how this was fixed in 5.4 but here we have it again. has any one managed to fix this
05-12-2015 10:01 AM
we had the same issue and got the url filter to work properly with a workaround from tac
by adding a monitor rule with the same categories we tried to block above the block urls rule the filter seems to work as it should. by adding this the website is first categorized and then the blocking rule matches
i hope this was helpful!
06-06-2016 10:48 PM
06-06-2016 11:02 PM
Hello Akzhol!
Yes, looks good.
But if you are using one of the latest Firepower versions this should not be a problem anymore. Currently I'm using version 6.0.1 and I'm very happy with it.
06-06-2016 11:37 PM
My Firepower version 6.0.1.
But it still doens't work.
URL Blocks works only 10-15 min but then allow pass traffic
06-07-2016 07:36 AM
We have version 6.0.1 with the exact same problem.
06-09-2016 10:21 PM
Hello Saleff,
Please open a new TAC service request with Cisco TAC so that they can verify and provide you the hotfix if the issue is confirmed.
Rate if this answer helps you.
Regards
Jetsy
06-09-2016 07:03 AM
Hi,
In the connection events. is it showing url category or showing as uncategorized ?
Thanks,
Ankita
06-09-2016 07:49 AM
When it is working the show up as category and when it is not blocking what it should it shows up as uncategorized.
Thanks
05-22-2015 07:11 AM
Try to upgraded to 5.4.1.1 Sourcefire and 5.4.0.2 for the sensors released past thursday 21/05.
I did it yesterday and it resolved some of my problems of non blocking sites or nos showing http response page.
04-08-2016 12:24 PM
In the end of the last year i had this same problem in a customer... but after update to version 5.4.0-4 the URL filtering works fine.
Today i got the same problem again, but now i update to version 5.4.0-5 and after to 5.4.0-7, and still does not work.
06-07-2016 10:35 PM
Hello Team,
There are several bugs reported in version 5.4 and 5.4.x reported with the url filtering . Thus it would be really recommended to upgrade the version to 6.0 or highest since the url filtering is stable in this versions.Based on the error what you told, it looks like hitting a bug.
Regards
Jetsy
06-08-2016 05:23 AM
We have version 6.0.1 and it still has the same problem. It stop filtering at random for about ten minutes and then it works again.
06-08-2016 10:17 PM
Hello Team,
I have faced a similar issue where the URL filtering rule never works properly in version 6 .Sometimes it follows the AC policy rule and block it or allow it accordingly sometimes its not. Have you added any security zone to the interface options in the Device management. We have a known bug reported while using asa sfr with url filtering contains the security zone. We have hotfix available for this issue and issue can be resolved . To confirm it , you have to open a Cisco TAC request so that the engineer can work on it to verify and provide you the hotfix that is available. The issue is there in 6.0.0 as well as 6.0.0.1. Thus you need to install the hotfix based on the version that you have.
Rate if this answer helps you.
Regards
Jetsy
06-09-2016 06:10 AM
Thanks Jesty for the reply. I will forward this info to the TAC Engineer that is working on this case.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide