06-14-2017 07:40 AM - edited 03-12-2019 02:35 AM
I just built Cisco ASA with FirePower as Internet Gateway with full features. I would like to filter some URLs like Porn, Social Media, Streaming Media... However it's not working as expected. There are some issue like:
- I configured URL filter with category 'Adult and Pornography'. Then I tried to open some porn website such as https://xnxx.com and it was working. I monitored with Event Connection it allowed because this URL didn't in 'Adult and Pornography', it's unknown Category. I thought the issue related to the URL filtering DB. However CSI is up to date.
- I'm not sure why Youtube still working properly. I thought it may need some technique to filter.
06-14-2017 07:52 AM
That's odd. Cisco's FirePOWER products use Brightcloud's category and reputation service and that site definitely shows up as adult and pornography:
http://www.brightcloud.com/tools/url-ip-lookup.php
Can you share a screenshot of your relevant Access Control Policy rule and confirm that it has been successfully deployed?
06-14-2017 08:28 AM
I will screenshot and let you see the Rule Configuration and Connect Event which URL traffic proceed.
06-15-2017 01:47 AM
What ASA model are you using?
What version of FMC & Firepower module are you using?
06-15-2017 09:12 AM
I'm using Cisco Firepower 6.2.0 on Cisco ASA and I manage it by ASDM. Do you have any experiences to block Youtube? I have tried to block by category "Streaming Media" but it wasn't success.
Thanks,
Mano
01-06-2019 09:47 AM
if you need to block youtube then you need SSL encap/decap. because if a client type https://youtube.com than FP can not block this connection unless you have a SSL decap on box.
01-06-2019 09:02 AM
It looks no body have an answer to weird behaviour of FP(FMC 6.2.2) .We are struggling since one month and even cisco TAC doesn't have answer yet
01-06-2019 09:32 AM
I had a same issue after spending countless hours i find the issue. I am using 5506-x with URL,MAL,IPS lic on FMC.
whent you define a rule in ACP make sure you leave any your security zone and any interface i have attach the photo. once done then tetst it will work. i am uisng 6.2. and its blocking the adult and dirty websites.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide