cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
938
Views
0
Helpful
5
Replies

URL Filtering on ASA 5520?

whiteford
Level 1
Level 1

Hi, I am currently filtering users web sites internally via a product called Surf Control (now owed my Websense). The thing is I have now configured the ASA to accept VPN connections from users. They can get access to the internet but it is not monitored. Currently the inside port of the ASA plugs into a Cisco 3750 vlan switch where there is a surfcontrol server too and port mirroring. I think the VPN users bypass this and go through the outside interface instead so they are not filtered.

What do other network guys do to block websites?

thanks

5 Replies 5

srue
Level 7
Level 7

so the URL filtering works normally as it should for local LAN users. It's just for remote access vpn users that it's not working for?

Yeah that's right

Any more anwers on this? I am having the same issue.

Yup, I think vpn users redirect from the outside interface to the internet.

Hi there

First of all, you need to make sure your users are using the proxy in there settings.

Then, all you need to do is a static nat from your proxy server to a public address from your pool. Then create a rule just to allow ftp,ssl,and http from your proxy server only.

I would also make sure that you have not enabled traffic between 2 or more hosts connected to the same interface, this may be what it is.

cheers

Carl

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: