cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
917
Views
5
Helpful
3
Replies

Problem with URL filtering ASA5516 with firepower services

rayala00111
Level 1
Level 1
Hello everyone, I have a problem with my ASA5516, it does not filter the communications via URL FILTERING, in the logs I can see only the default policy (trust all traffic), I have the license URL FILTERING enabled, and the access policy enabled, I do not have FMC, the policy is well configured to redirect traffic to the sfr module, any idea what may be happening? , I can not connect to service.brightcloud.com from the srf console, I have the dns configured, it does not filter manually created objects.

Thank you very much
3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

You need to (at a minimum) monitor URLs in your ACP. Can you share a screenshot of your Access Control Policy in which you have configured URL monitoring or filtering?

Hi Marvin

 

the problem was that there was no communication between the IP address of the SFR module and the internet, at this moment it is communicating with the internet through the internal network and it is already filtering but I would like it to go online through the same FW.

Please dont post your messages in code text boxes. It makes them very difficult to read.

 

Your URL lookups always need to go out from the sfr module. That module can use the same firewall as a gateway but you cannot use the firewall's external (or internal) address as the source IP.

Review Cisco Networking for a $25 gift card