10-24-2010 09:10 PM - edited 03-11-2019 11:59 AM
Does default regex in asa 5520 cause problems with any sites. our clients are facing problems with some website. Occurs when some core modules are used.
My asa has regex for aspx . this wasnt configured , but seems to be default.
Appreciate if someone can point on methods to verify the regex doesnt block anything or any other aspect in asa.
TIA.
Solved! Go to Solution.
10-24-2010 10:12 PM
Hello
Regex are on the configuration but they are not applied, once you apply it under a layer 7 policy map is when they get active, once quick question, Do you have HTTP inspection under the policy map? Does it have drops?
Let me know.
Mike
10-24-2010 10:12 PM
Hello
Regex are on the configuration but they are not applied, once you apply it under a layer 7 policy map is when they get active, once quick question, Do you have HTTP inspection under the policy map? Does it have drops?
Let me know.
Mike
10-24-2010 10:28 PM
http doesnt exist in policy, hence nothing seen.
10-24-2010 10:46 PM
Hello
Thanks for the reply, I see, do you have any CSC module or Websense configuration? Those are the only things that can be messing with you at this point, have you already identified the type of sites or the websites you cannot access?
Let me know
Mike
10-24-2010 10:58 PM
You can do a "show service-policy" to see if drops are incrementing in any of the fields. You can also do a "show asp drop" to see all the reasons and counts that packets are dropping. Could you enlighten us as to what regex configuration you suspect is the issue?
10-24-2010 11:07 PM
He already said he did not have any
10-24-2010 11:10 PM
My asa has regex for aspx
This part confused me, I wasn't sure what was meant by this.
10-24-2010 11:09 PM
regex _default_http-tunnel "[/\\]HT_PortLog.aspx
this line in regex put me into thinking. the said website is also aspx , which made me check for any relevance for this.
thanks.
10-24-2010 11:13 PM
If it is not on a layer 7 policy map, then it is not applied or doing anything, I would suggest you to take a look at any websense configuration, CSC module policy and also to try to hook up a computer outside of the firewall and try to go to these websites and check if you get the same results.
Mike
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: