CSS11503 URL filtering
Hi all,
I have a pair of redundant CSS11503 load-balancing two HTTP servers. I need to permit access to specific subset of URLs on those two HTTP servers to anybody on the Internet, while rest of the URLs should be allowed for specific range(s) of IP addresses.
- permit any to access /games/scores/*
- permit some/range to access /*
- deny the rest
I'm running a two-armed CSS setup, meaning a public VIP known by external users. Requests to the VIP are load-balanced on two internal/RFC1918 HTTP servers.
I'm running WebNS 7.20.
Anybody can shed some light into this issue?
Thanks,
haver
you could create 2 content rules with the same VIP address but different url:
ie:
owner mycompany
content web_all
vip 10.1.1.1
url "/*"
content web_restricted
vip 10.1.1.1
url "/games/scores/*"
Then create ACL like this
acl 1
clause 5 deny any destination content web_restricted
clause 10 permit any any destination content mycompany/web_all
The trick is to use 'content ' as the destination.
This is not complete but you should get the idea from this.
Regards,
Gilles.
Similar Messages
-
Web Filtering / URL Filtering
Dear All,
I am looking forward to buy the cisco ASA Firewall with the below mentioned part number.
ASA5525-SSD120-K9 kindly please let me know whether it supports WEB Filtering / URL Filtering.
or do i need to go for any other model or license.
Awaiting your quick responses as it is very urgent.
Responses are highly appreciated..That's the hardware
You also need a software subscription for the URL/web stuff/IPS
Near the bottom of this page: http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/data_sheet_c78-701659.html
there is a chart with the options and part numbers. -
Websense URL Filtering is not working in transparent proxy mode
The "sh ip wccp web-cach detail" show that the redirection to CE cluster (5 of them)is working but the url filtering doesnt work at all. The Websense server is on the same VLAN as all the 5 CE. This thing happened when we reconfigured the wccp router list in all the 5 CE point to the msfc vlan ip from the loopback ip address of the msfc. But the strange thing is the filtering work well when we manually configured the proxy server in the internet explorer point to the CE. Any advise?
Thanks.
WilliamProblem is due to absense of Host header field . Most of the browsers will send host header field. But in HTTP/1.0 Host header is not a must , though most of the browsers send it.
-
Trend Micro Interscan URL Filtering policies not working
I have just inherited a ASA 5520 with a TrendMicro InterScan for CSC SSM (version 6.6.1125.0) with both Base and Plus licenses. We have several URL filtering policies setup with AD group checking via the Domain Controller Agents. These rules are currently in the order of most strict (only a couple of explicitly identified users and one IP address), then two different policies that block less content than the global list (each assigned to LDAP list based on AD group membership), then our global URL Filtering policy.
The most common problem I have is when I try to open a site for one of the LDAP groups the site does not become accessible until I also add it to the HTTP Exceptions list on the Global Policy thus opening it for all users.
Any suggestions?/* Style Definitions */
table.MsoNormalTable
{mso-style-name:"Table Normal";
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-priority:99;
mso-style-qformat:yes;
mso-style-parent:"";
mso-padding-alt:0in 5.4pt 0in 5.4pt;
mso-para-margin-top:0in;
mso-para-margin-right:0in;
mso-para-margin-bottom:10.0pt;
mso-para-margin-left:0in;
line-height:115%;
mso-pagination:widow-orphan;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
mso-ascii-font-family:Calibri;
mso-ascii-theme-font:minor-latin;
mso-fareast-font-family:"Times New Roman";
mso-fareast-theme-font:minor-fareast;
mso-hansi-font-family:Calibri;
mso-hansi-theme-font:minor-latin;
mso-bidi-font-family:Arial;
mso-bidi-theme-font:minor-bidi;}
Thanks,
Right now I removed tick form Leisure Time. But everything is open which I blocked.
But I wanna blocking 24hrs but During 7 to 8 I wanna leisure time.
If I tick marked all categories for both Work and Leisure then all things blocked
If I removed tick from Leisure column then everything open…
Kindly View attached Screen Shot -
ProtectLink Web Protect URL Filtering not working
Good day!
Please help.
We have a problem on our RV042 router.
The Protectlink WebProtect URL filtering is not working.
When we first activate the service (Nov. 12), it worked for a few days, then 2 days ago, our internet connection got problems. But yesterday, our ISP fix the problems on our internet connection, but the URL filtering of WebProtect is not working anymore even if it is enable, up to this time.
What should we do about this problem?
Thanks in advance for your kind replies!i have installed TMG 2010 and created url filtering rule for facebook.com but that problem
is ever after five minutes i can see that the users can access facebook. and then i check in TMG MMC so i can see that the Category Query says me that facebook.com is unknown....but just after five minutes i can see facebook has been automatically blocked
and i can also see in Category Query it says me facebook is in blog/wiki category...
so why it is changing automatically every after 5 or 10 minutes :( ?
where is the problem ???
i need your help please !! -
Hello. I have the following problem. I try to implement the url filtering feature on a cisco 2811 router and whenever i enable the parameter map patterns the router retuns (after some time)
%Unable to compile obj regex...
My config is
parameter-map type urlfpolicy local URLFILTER
alert off
block-page message "THE REQUEST WAS BLOCKED BY YOUR ROUTER FIREWALL"
parameter-map type urlf-glob ALLOW-URL
pattern *.cisco.com
pattern cisco.com
parameter-map type urlf-glob DENY-URL
pattern *
class-map type urlfilter match-any ALLOW-URL
match server-domain urlf-glob ALLOW-URL
class-map type urlfilter match-any DENY-URL
match server-domain urlf-glob DENY-URL
class-map type inspect match-all INSPECT-HTTP
match protocol http
policy-map type inspect urlfilter URL-FILTER
parameter type urlfpolicy local URLFILTER
class type urlfilter ALLOW-URL
allow
class type urlfilter DENY-URL
reset
log
policy-map type inspect IN-OUT
class type inspect VPN-TRAFFIC
inspect
class type inspect INSPECT-HTTP
inspect
service-policy urlfilter URL-FILTER
class type inspect INTERNET-TRAFFIC
inspect
class class-default
drop
The result is that the router blocks ALL webpages without giving a block page message. Any help would be greatly appreciated.I have same problem. Reboot router don't help me. Firewall allow all traffic and blocked url too.
-
PIX515 URL filtering doen't work
Dear collegues,
I have one outside interface with global IP address 1.1.1.1 and two inside.
Both inside interfaces restrict and non_restrict have private IP addresses.
I tried to filter some URLs on PIX515 IOS 7.2, only on restrict interface but my filter does not work.
I can access prohibited URL from restrict interface.
Could you tell me what's wrong in my URL filtering?
Here is my config:
PIX Version 7.2(2)
hostname pixfirewall
enable password 8Ry2YjIyt7RRXU24 encrypted
names
interface Ethernet0
nameif outside
security-level 0
ip address 1.1.1.1 255.255.255.252
interface Ethernet1
nameif restrict
security-level 50
ip address 192.168.2.1 255.255.255.128
interface Ethernet2
nameif non_restrict
security-level 100
ip address 192.168.2.129 255.255.255.192
passwd 2KFQnbNIdI.2KYOU encrypted
regex domainlist1 "\.facebook\.com"
regex domainlist2 "\.twitter\.com"
regex domainlist3 "\.youtube\.com"
ftp mode passive
access-list inside_mpc extended permit tcp any any eq www
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
nat (restrict) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 1.1.1.1 1
class-map type regex match-any DomainBlockList
match regex domainlist1
match regex domainlist2
match regex domainlist3
class-map inspection_default
match default-inspection-traffic
class-map type inspect http match-all BlockDomainsClass
match request header host regex class DomainBlockList
class-map httptraffic
match access-list inside_mpc
policy-map type inspect http http_inspection_policy
parameters
protocol-violation action drop-connection log
class BlockDomainsClass
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp
policy-map inside-policy
class httptraffic
inspect http http_inspection_policy
service-policy global_policy global
service-policy inside-policy interface restrict
endHi,
can you try inspecting http.
Regards.
Alain -
URL filtering replacing with web usage control
I come to know the URL filtering in ironport is replacing with the advanced web usage control. May i know from which version its introducing? Any upgradation procedure?
What are the changes will take place after the upgradation & what kind of functionality will be available with Web Usage Control.
Please clarify in detail.
Thanks in advance
SivaI don't remember when the web Usage controls was introduced... I'm going to guess 7.0?
To upgrade your box to the the current version, click on System Administration>System Upgrade. Click on the Available Upgrades and see what's available for your hardware. If nothing is there, contact your reseller.
Review the release notes for the version you want to upgrade to. http://www.cisco.com/en/US/products/ps10164/prod_release_notes_list.html
Select the version you want, check the box to save the config, you can also have it email you the config. Make sure to uncheck the "Mask passwords..." so that if you have to reload this config on something, it works properly.
There are a huge number of changes in how web usage control works, and the visibility it gives you into what apps users are using and how those applications work. Far to many to go into here. Look at this document:
Chapter 18. http://www.cisco.com/en/US/docs/security/wsa/wsa7.5/user_guide/WSA_7.5.0_UserGuide.pdfhttp://www.cisco.com/en/US/docs/security/wsa/wsa7.1/user_guide/Cisco_IronPort_AsyncOS_7.1.0_User_Guide_for_Web_Security_Appliances.pdf -
Hi All,
whenever I setup URL filtering in 1841 router with policy-map type http and zone-pair command, I experience 100% CPU spike. is there any workaround?
thanks for any suggestion
AlexDeep packet inspection for URL filtering is pretty much CPU intensive, I am afraid that without HW upgrade, there is nothing you can do about that.
Do you monitor CPU utilization with correlation to traffic load on device?
Best Regards
Please rate all helpful posts and close solved questions -
Url filtering Route policy Firewall ?
Hello,
I'd like to know if it's possible to make a route policy (based on an identity matched by url white list) that redirect http trafic to a firewall (Juniper SSG550M).
The objectif is to separate traffic depending on url request as professionnal and non professionnal traffic, but Juniper can't be used as Upstream Proxy because it can't be use as a proxy. So, is it possible to create 2 "Direct connection" routing policies and specify 2 différents gateway ?
Or, if you have any other idea to separate traffic depending on url, I take it !
Regards,
Romain.Hi Stella
AFAIK you can do URL filtering provided that you have a websense server installed at your site.
do refer this link for more info on the same..
http://www.cisco.com/en/US/partner/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008008d1f7.html
regds -
So I've started to test the URL filtering capabilities on our C670s. So far I have found that there are quite a few false positives or incorrectly categorized web sites. Is there any mechanism in place to request a reclassification of a website?
JasonHi Robert,
Cisco Ironport is not having any phishing category.
https://securityhub.cisco.com/web/submit_urls
Using the above link, how we can report phishing URL.
many emails with phishing url.
FYI
Check the boxes and then assign a category:
Check
URL
Category
www.mirror.co.uk/news/uk-news/lottery-winner-give-away-26million-3967400
News
ithelpdeskservice.wix.com/service
Computers and Internet
mail.a4.3space.info
Computers and Internet
www.arabyonline.com
News
box1box1.wix.com
Computers and Internet
mypartners.netotrade.com
Business and Industry
--Sajid-- -
Hi,
I need to buy a firewall with some basic URL filtering. I only need to deny access to some URL and not using a service like Websense or something like that.
I would like to do this with an ISR, like 2800 family, because I don't need anti-x features but only basic firewalling, VPN, and Voice features.
The other option is to use ASA 5520, but I would like to make the simple URL filtering without the need to use CSC module.
Is there any way to to this?
Mario.There is no need to go for an ASA. A 2800 isr will do.
Refer the following url's for more details,
http://cisco.com/en/US/products/sw/iosswrel/ps5460/prod_bulletin09186a00801af451.html
http://cisco.com/en/US/products/ps6643/products_white_paper0900aecd804abb11.shtml -
URL filtering ACE after description of SSL traffic
We currently have a Cisco CSS11501 which we have configured with SSL offloading.
We offload the SSL traffic and after description of the ssl traffic we perform URL filtering.
Can the Ace 4710 Appliance do the same?
I have attached the current configuration of the css.
Regards,
RichardWith the below config
Traffic matching 10.10.10.10:443 will be SSL offloaded and then
will be loadbalanced using rservers in Serverfarm "APP1-SFARM" if
the request includes "/matchthis".
ssl-proxy service APP1-SSL-PROXY
key default-key.pem
cert default-cert.pem
class-map match-all APP1-443-VIP
2 match virtual-address 10.10.10.10 tcp eq https
class-map type http loadbalance match-any APP1-URLMAP
2 match http url /matchthis.*
policy-map type loadbalance first-match APP1-Policy
class APP1-URLMAP
serverfarm APP1-SFARM
policy-map multi-match VIPS-VLAN79
class APP1-443-VIP
loadbalance vip inservice
loadbalance vip icmp-reply active
loadbalance policy APP1-Policy
ssl-proxy server APP1-SSL-PROXY
HTH
Syed iftekhar Ahmed -
A customer called me to ask about URL filtering. He bought a 506 a little over a year ago. I haven't been on site to see exactly what IOS he has, but he wants to know if he can filter certain web sites from certain PCs. Of course the answer is yes, but I need to know more about the capabilities of the 506 URL filtering capabilities. Can I create a "White list" for certain PCs in an address range and allow full access to other PCs?
The real problem is on 3 PCs that midnight shift users like to use for porn surfing!
If the 506 can't do the filtering, then I may just add a local piece of software on the 3 problem PCs.
Any advice on the 506 capabilities would be appreciated.hi
You can use websense in addition to PIX F/W to filter the traffic based on the URL,which is most widely deployed,but again u need to decide the cost factor involved in doing so.
regds -
Dear All,
We plan to change the URL filterting system from our network. currently we use Websense. our management has decided to cancel the extension due to market slowdown.
Can u guide to find a cheap and best URL filtering solution for our network.
Thanks in advance
ShibuWe can't say which is best for your network, only you can. However there are some good open-source proxies such as SQUID.
www.squid-cache.org
http://www.google.com/#hl=en&q=open+source+proxy+server&aq=4&oq=open+source+pro&aqi=g10&=Google+Search&=I%27m+Feeling+Lucky&fp=1mZ_-PL2Zjc
Maybe you are looking for
-
Hi All, I want to add a mask to a text input field, so the user can only type numbers on it (integers, more specifically), I think that this is done by a Converter but it doesn't add the apropriate javascript. How Can I do this? And if I want to mask
-
HT201250 Using Time Machine as an external hard drive
I backed up my iMac with an external hard drive using Time Machine; can I delete all the data from my iMac now? My real goal is to use the 1TB external hard drive I just got to store all my music, photos, and other files on. I want to clear all the s
-
Hi In ESS when the User is trying to click on Leave request - Error displayed as below : error displayed as : "A critical error has occured. Processing of the service had to be terminated. Unsaved data has been lost. Please contact your system admini
-
Choosing variant blocks radiobutton values. Is there a work around?.
Dear Forum participants, I have a simple radiobutton group: SELECTION-SCREEN BEGIN OF BLOCK B1 WITH FRAME. PARAMETERS : R3ALL RADIOBUTTON GROUP RG3, R3DEL RADIOBUTTON GROUP RG3, R3CCC RADIOBUTTON GROUP RG3. SELECTION-SCRE
-
Der experts ! I enabled withholding tax management in General Settings and in Item master data. Also I defined a withholding tax. When trying to enter a tax, on a AP invoice, the fields 'WTax Liable' displays 'No' and it is unchangeable ('Yes' is no