URL Filtering on ASA 5520?

Unanswered Question
Feb 27th, 2008

Hi, I am currently filtering users web sites internally via a product called Surf Control (now owed my Websense). The thing is I have now configured the ASA to accept VPN connections from users. They can get access to the internet but it is not monitored. Currently the inside port of the ASA plugs into a Cisco 3750 vlan switch where there is a surfcontrol server too and port mirroring. I think the VPN users bypass this and go through the outside interface instead so they are not filtered.

What do other network guys do to block websites?


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
srue Wed, 02/27/2008 - 12:26

so the URL filtering works normally as it should for local LAN users. It's just for remote access vpn users that it's not working for?

nomair_83 Mon, 06/16/2008 - 21:16

Yup, I think vpn users redirect from the outside interface to the internet.

carl_townshend Thu, 09/04/2008 - 05:33

Hi there

First of all, you need to make sure your users are using the proxy in there settings.

Then, all you need to do is a static nat from your proxy server to a public address from your pool. Then create a rule just to allow ftp,ssl,and http from your proxy server only.

I would also make sure that you have not enabled traffic between 2 or more hosts connected to the same interface, this may be what it is.




This Discussion