06-25-2015 02:09 AM - edited 03-11-2019 11:11 PM
hi all,
currently, we're doing web filtering (on layer 3) via open dns cloud service.
i know we can do regex and use a CX module.
is there any other ways (or option) to do web filtering/DPI on the application layer with a NGN 5500-X firewall?
http://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#pgfId-137099
http://www.cisco.com/c/en/us/td/docs/security/asacx/compatibility/cx_prsm_comp.html#pgfId-53163
06-25-2015 07:59 AM
You can also do SourceFire on the 5500-X, with the purchase of some licensing and a SSD if you don't already have one.
If those don't work, you can do WCCP with popular web-filters such as WebSense, etc.
06-25-2015 07:03 PM
hi,
i've made some search on source fire but can this be standalone? meaning, i don't need to setup firesight management for the 5500x?
is there a way or a command to check if there's an SSD installed on the ASA 5500-x? is it shipped by default? i can't see it via show module and show inventory output.
wccp to another box is not an option here.
06-25-2015 10:06 PM
i think i'm going for scansafe/cisco cloud web security since it uses our existing 5500 and some new 5500x ASAs.
http://www.cisco.com/c/en/us/products/collateral/security/adaptive-security-appliance-asa-software/whitepaper_C11-715169.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide