ASA 5520: How to define an URL as destination in a rule

Unanswered Question
Feb 18th, 2010

Hi. I would like to define a URL(www.google.fr

for example) in the destination field instead of an predefined object because the IP address for www.google.fr

may change. How should I do?

Thanks for your replies

Christian

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Panos Kampanakis Thu, 02/18/2010 - 13:18

Christian,

You cannot use urls on an ACL.

You can sue names in the config and assign them an ip address and use them in the ACL. If you want to change the ip you change it in the name not the ACL.

But you cannot use a url on the ASA ACL and have the ASA resolve it.

I hope it helps.

PK

maintenance.artesys Fri, 02/19/2010 - 05:53

Thank you all for your replies.

To answer Kusankar, let me tell you that I just want to allow access to www.google.fr, for example, from internal hosts. But, as you know, google has a lot of IP address(see the nslookup bellow) and I don't want to enter a name for each IP...!

Is it not simply possible to create à dynamic object?

----------------------

C:\WINDOWS>nslookup www.google.fr
Serveur :  ouessant.artesys-osiex.local
Address:  192.168.2.16

Réponse ne faisant pas autorité :
Nom :    www.l.google.com
Addresses:  209.85.227.147, 209.85.227.99, 209.85.227.103, 209.85.227.104
          209.85.227.105, 209.85.227.106
Aliases:  www.google.fr, www.google.com

Thanks

Christian

Panos Kampanakis Fri, 02/19/2010 - 06:04

No.

You can group many names in one object, but they won't be dynamic, you will need to change ip addresses manually.

PK

Actions

This Discussion