cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2061
Views
5
Helpful
4
Replies

How to allow *.website in ASA

Brad_Shawh
Level 1
Level 1

Hello

We are on ASA 9.8

 

https://docs.microsoft.com/en-us/previous-versions/system-center/configuration-manager-2007/bb693717(v=technet.10)?redirectedfrom=MSDN

 

We have a requirement to allow all microsoft updates through ASA.

 

How can this be achieved? Thank you.

1 Accepted Solution

Accepted Solutions

You cannot do the wildcard in ASA ACLs with FQDN objects:

https://community.cisco.com/t5/network-security/asa-wildcard-fqdn-object-acl/m-p/3062315

So you would need to specify FQDNs of Microsoft domains without using wildcards.

View solution in original post

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

By default outbound traffic isn't blocked and outside traffic that's returning as part of a connection that was established from inside is allowed.

So, unless you're restricting outbound traffic, nothing needs to be done.

Thank you.

 

Yes, we are restricting traffic from inside and want updates from microsoft to be allowed.

You cannot do the wildcard in ASA ACLs with FQDN objects:

https://community.cisco.com/t5/network-security/asa-wildcard-fqdn-object-acl/m-p/3062315

So you would need to specify FQDNs of Microsoft domains without using wildcards.

Thank you, I'll use firepower!

Review Cisco Networking for a $25 gift card