cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1102
Views
3
Helpful
8
Replies

regex expressions in asa

suthomas1
Level 6
Level 6

Does default regex in asa 5520 cause problems with any sites. our clients are facing problems with some website. Occurs when some core modules are used.

My asa has regex for aspx . this wasnt configured , but seems to be default.

Appreciate if someone can point on methods to verify the regex doesnt block anything or any other aspect in asa.

TIA.

1 Accepted Solution

Accepted Solutions

Maykol Rojas
Cisco Employee
Cisco Employee

Hello

Regex are on the configuration but they are not applied, once you apply it under a layer 7 policy map is when they get active, once quick question, Do you have HTTP inspection under the policy map? Does it have drops?

Let me know.

Mike

Mike

View solution in original post

8 Replies 8

Maykol Rojas
Cisco Employee
Cisco Employee

Hello

Regex are on the configuration but they are not applied, once you apply it under a layer 7 policy map is when they get active, once quick question, Do you have HTTP inspection under the policy map? Does it have drops?

Let me know.

Mike

Mike

http doesnt exist in policy, hence nothing seen.

Hello

Thanks for the reply, I see, do you have any CSC module or Websense configuration? Those are the only things that can be messing with you at this point, have you already identified the type of sites or the websites you cannot access?

Let me know

Mike

Mike

You can do a "show service-policy" to see if drops are incrementing in any of the fields. You can also do a "show asp drop" to see all the reasons and counts that packets are dropping. Could you enlighten us as to what regex configuration you suspect is the issue?

He already said he did not have any

Mike

My asa has regex for aspx 

This part confused me, I wasn't sure what was meant by this.

regex _default_http-tunnel "[/\\]HT_PortLog.aspx

this line in regex put me into thinking. the said website is also aspx , which made me check for any relevance for this.

thanks.

If it is not on a layer 7 policy map, then it is not applied or doing anything, I would suggest you to take a look at any websense configuration, CSC module policy and also to try to hook up a computer outside of the firewall and try to go to these websites and check if you get the same results.

Mike

Mike
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card