02-27-2008 08:55 AM - edited 03-11-2019 05:09 AM
Hi, I am currently filtering users web sites internally via a product called Surf Control (now owed my Websense). The thing is I have now configured the ASA to accept VPN connections from users. They can get access to the internet but it is not monitored. Currently the inside port of the ASA plugs into a Cisco 3750 vlan switch where there is a surfcontrol server too and port mirroring. I think the VPN users bypass this and go through the outside interface instead so they are not filtered.
What do other network guys do to block websites?
thanks
02-27-2008 12:26 PM
so the URL filtering works normally as it should for local LAN users. It's just for remote access vpn users that it's not working for?
02-27-2008 12:34 PM
Yeah that's right
06-16-2008 11:30 AM
Any more anwers on this? I am having the same issue.
06-16-2008 09:16 PM
Yup, I think vpn users redirect from the outside interface to the internet.
09-04-2008 05:33 AM
Hi there
First of all, you need to make sure your users are using the proxy in there settings.
Then, all you need to do is a static nat from your proxy server to a public address from your pool. Then create a rule just to allow ftp,ssl,and http from your proxy server only.
I would also make sure that you have not enabled traffic between 2 or more hosts connected to the same interface, this may be what it is.
cheers
Carl
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide