Problem In Policy

Unanswered Question
Sep 20th, 2009
User Badges:
  • Silver, 250 points or more

Dear All

I am binding the policy in ASA 5500, everthing works fine except we are not able to download the mail attachment from MSN.

The ASA OS Version is 8.2(1).

regex domainlist2 ".*sandai.*"

regex domainlist4 ".*megaupload.*"

regex domainlist5 ".*sendspace.*"

regex domainlist6 ".*rapidshare.*"

access-list inside_mpc extended permit tcp any any eq www

access-list inside_mpc extended permit tcp any any eq 8080

class-map type regex match-any DomainBlockList

match regex domainlist2

match regex domainlist4

match regex domainlist5

match regex domainlist6

class-map type inspect http match-all BlockDomainsClass

match request header host regex class DomainBlockList

class-map httptraffic

match access-list inside_mpc

policy-map type inspect http http_inspection_policy


protocol-violation action drop-connection

match request method connect

drop-connection log

class BlockDomainsClass

reset log

policy-map inside-policy

class httptraffic

inspect http http_inspection_policy

service-policy inside-policy interface Internal


shivlu jain

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Farrukh Haroon Mon, 09/28/2009 - 04:14
User Badges:
  • Red, 2250 points or more

Try removing the non-standard HTTP check and see how it goes:

no protocol-violation action drop-connection

Or change the action from drop to logging only




This Discussion