URL blocking to be applied to specific users
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2010 04:40 AM - edited 03-11-2019 10:07 AM
Dear Team,
I am having ASA firewall 5520. I want to block yahoo mail, gmail using regex for particular users only.
How to go about it?
Thanks and Regards,
Divya
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2010 09:47 AM
The first response on this particular post to the forum pretty much sums up how it's done. I've tried it per this gentleman's response and it does work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2010 01:43 PM
Unfortunatelly you cannot block the sites per user. You can block it based in the access-list that you apply to the Class-map but not based in the username of a user in a domain controller for example.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2010 06:22 PM
Divya,
The CSC module can do this based on active directory user accounts. It goes in the slot on the back of the ASA. Besides that you need to specify IP address and not username to block it.
You can read about the CSC module here: http://www.ciscosystems.co.ck/en/US/docs/security/csc/csc62/administration/guide/csc8.html
Another alternative is to use websense or N2H2 server on the inside to do content filtering.
-KS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2010 08:52 PM
If you want to block the urls on the ASA only then use example in https://supportforums.cisco.com/docs/DOC-1268#Allow_every_url_for_specific_hosts_block_specific_urls_for_the_rest
It will give you exactly what you want.
I hope it helps.
PK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2012 05:00 AM
HI expert,
Would you please help me in this issue I have ASA 5510 and I need to block URL to be applied to specific users not using the IP address. I integrate ASA with my active directory now it’s (ASA) detecting the users from my domain but he is not applied the rules on the users.
It’s only working using the IP address using trend micro content security
Any help in this issue.
if you have any idea please contact me on my email :
Thanks.
