cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1034
Views
3
Helpful
4
Replies

DNS in firewall rule

suthomas1
Level 6
Level 6

Hi,

What if we need to get in rule to permit certain site on ASA with the sites domain name & not based on IP. Can this be done by just putting in the site name"www.abc.com" or is there any other way.Please help.

Thanks.

4 Replies 4

sachinraja
Level 9
Level 9

Hello Thomas

If you want to restrict access through URL's, you need to have a URL filtering software seperately , or have a CSC module with the ASA.. CSC can do content filtering.. With a plain ASA, you can just restrict traffic with IP addresses..

Hope this helps.. all the best..

Raj

How can i determine if my firewall has a CSC module.Any commands to check this out?

Thanks.

"How can i determine if my firewall has a CSC module"

You may use command show module 1 detail to verify this

Hi Thomas,

it can be done through regex (if u dont have a third party server like websense or n2h2)

http://supportwiki.cisco.com/ViewWiki/index.php/ASA_URL_filtering

or

http://www.cisco.com/application/pdf/paws/100535/asa-8x-regex-config.pdf

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card