cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
560
Views
0
Helpful
3
Replies

Which product can chase internal user access internet web site?

cwhlaw2009
Beginner
Beginner

Dear All,

My client is using ASA 5512, they want to check and record their internal users (Employees) accessed what web site (HTTP, HTTPS, FTP etc.).

I haven't any idea which cisco product or other can do this.

THX

2 Accepted Solutions

Accepted Solutions

Marvin Rhoads
Hall of Fame Community Legend Hall of Fame Community Legend
Hall of Fame Community Legend

The FirePOWER module on the ASA 5512-X, when licensed and configured with proper policy, can do this.

The ASA 5512-X by itself cannot.

If you can share "show inventory" and "show module" we can get some clue about the appliance's readiness and ability to run the module. We would be looking for the required SSD and installed sfr module type.

View solution in original post

Marvin Rhoads
Hall of Fame Community Legend Hall of Fame Community Legend
Hall of Fame Community Legend

FirePOWER can easily restrict access to websites by category - whether they are http or https. You need only the URL Filtering license for that.

If you want to DECRYPT and inspect https traffic and make decisions based on things like micro applications (e.g allow Facebook posting but prohibit Facebook games) then you need to do a lot more. The FirePOWER module can do it, but you need an enterprise PKI that can issue a certificate that the clients trust and can act as a man-in-the-middle. It also takes a lot more processing power. As a result, your throughput can go WAY down. It is not something you would want to do an a 5512-X platform unless a throughput of about 20 Mbps was acceptable. 

However, that limitation is shared by all web filtering services or appliances.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame Community Legend Hall of Fame Community Legend
Hall of Fame Community Legend

The FirePOWER module on the ASA 5512-X, when licensed and configured with proper policy, can do this.

The ASA 5512-X by itself cannot.

If you can share "show inventory" and "show module" we can get some clue about the appliance's readiness and ability to run the module. We would be looking for the required SSD and installed sfr module type.

One more question, client said they want to filter web site such as HTTPS 

After using FirepOWER, do they need buy websense or smartfilter? or FirePower only can filter HTTPS, http etc website?

THx

Marvin Rhoads
Hall of Fame Community Legend Hall of Fame Community Legend
Hall of Fame Community Legend

FirePOWER can easily restrict access to websites by category - whether they are http or https. You need only the URL Filtering license for that.

If you want to DECRYPT and inspect https traffic and make decisions based on things like micro applications (e.g allow Facebook posting but prohibit Facebook games) then you need to do a lot more. The FirePOWER module can do it, but you need an enterprise PKI that can issue a certificate that the clients trust and can act as a man-in-the-middle. It also takes a lot more processing power. As a result, your throughput can go WAY down. It is not something you would want to do an a 5512-X platform unless a throughput of about 20 Mbps was acceptable. 

However, that limitation is shared by all web filtering services or appliances.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers