cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1534
Views
0
Helpful
4
Replies

How to block url for HTTPS traffic without SSL decpryptions on FTD 6.2.3?

slv_slv
Level 1
Level 1

Hi All

 

I'm using FTD on ASA 5506x v6.2.3.16-59 (managed by Firepower Device Management) with latest updates.

I have rule with app filter HTTPS and url category which should be blocked Dating (just for testing)

Screenshot_66.jpg

as you can expect this rule is not working correclty - thats why I'm asking you for help here

Screenshot_67.jpg

 

Traffic hit correct sec rule, so app detection is working fine, also url categoryzation seems to be fine.

Why this traffic is allowed?  Whats wrong here ?

 

I wouldn't do a SSL decrypt becase my device is too small, but based on SSL cert SNI block urls.

 

Regards

Slawek

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

you need to bring up the rule above the 2nd rule, as per the screenshot, your 2nd rule has any any HTTPS allowed.

 

here is a guide :

 

https://www.cisco.com/c/en/us/support/docs/smb/routers/cisco-rv-series-small-business-routers/1332-how-to-purchase-and-setup-web-filter-licensing-on-the-rv340.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

you need to bring up the rule above the 2nd rule, as per the screenshot, your 2nd rule has any any HTTPS allowed.

 

here is a guide :

 

https://www.cisco.com/c/en/us/support/docs/smb/routers/cisco-rv-series-small-business-routers/1332-how-to-purchase-and-setup-web-filter-licensing-on-the-rv340.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

For me, it looks like it worked as expected and the session was blocked.

@karsten 

Where do you see action block on provided screenshots? This webpage is fully loaded on my laptop.

The top of your screenshot says "Connection Event ---- Block".

Did you clear your browser cache or try opening the site in a private/incognito browser session?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card