08-19-2016 04:18 AM - edited 02-21-2020 05:54 AM
Dear All,
My client is using ASA 5512, they want to check and record their internal users (Employees) accessed what web site (HTTP, HTTPS, FTP etc.).
I haven't any idea which cisco product or other can do this.
THX
Solved! Go to Solution.
08-19-2016 06:11 PM
The FirePOWER module on the ASA 5512-X, when licensed and configured with proper policy, can do this.
The ASA 5512-X by itself cannot.
If you can share "show inventory" and "show module" we can get some clue about the appliance's readiness and ability to run the module. We would be looking for the required SSD and installed sfr module type.
08-21-2016 06:25 PM
FirePOWER can easily restrict access to websites by category - whether they are http or https. You need only the URL Filtering license for that.
If you want to DECRYPT and inspect https traffic and make decisions based on things like micro applications (e.g allow Facebook posting but prohibit Facebook games) then you need to do a lot more. The FirePOWER module can do it, but you need an enterprise PKI that can issue a certificate that the clients trust and can act as a man-in-the-middle. It also takes a lot more processing power. As a result, your throughput can go WAY down. It is not something you would want to do an a 5512-X platform unless a throughput of about 20 Mbps was acceptable.
However, that limitation is shared by all web filtering services or appliances.
08-19-2016 06:11 PM
The FirePOWER module on the ASA 5512-X, when licensed and configured with proper policy, can do this.
The ASA 5512-X by itself cannot.
If you can share "show inventory" and "show module" we can get some clue about the appliance's readiness and ability to run the module. We would be looking for the required SSD and installed sfr module type.
08-21-2016 05:44 PM
One more question, client said they want to filter web site such as HTTPS
After using FirepOWER, do they need buy websense or smartfilter? or FirePower only can filter HTTPS, http etc website?
THx
08-21-2016 06:25 PM
FirePOWER can easily restrict access to websites by category - whether they are http or https. You need only the URL Filtering license for that.
If you want to DECRYPT and inspect https traffic and make decisions based on things like micro applications (e.g allow Facebook posting but prohibit Facebook games) then you need to do a lot more. The FirePOWER module can do it, but you need an enterprise PKI that can issue a certificate that the clients trust and can act as a man-in-the-middle. It also takes a lot more processing power. As a result, your throughput can go WAY down. It is not something you would want to do an a 5512-X platform unless a throughput of about 20 Mbps was acceptable.
However, that limitation is shared by all web filtering services or appliances.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide