The ASA firewall configures URL filtering. Detailed experimental steps

Source: Internet
Author: User

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/4C/9D/wKioL1RBFBrBKfS7AAD6ZFk9emY518.jpg "title=" FFF. PNG "alt=" Wkiol1rbfbrbkfs7aad6zfk9emy518.jpg "/>

Experimental topology diagram .... Server ip:202.168.1.10

Web www.cisco.com

Www.kkgame.com are built on the server with different hostname

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/4C/9D/wKioL1RBFLOS_83kAAOIl7aKaag938.jpg "title=" Capture 1. PNG "alt=" Wkiol1rbflos_83kaaoil7akaag938.jpg "/>

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/4C/9D/wKioL1RBFWXykNZTAALJsPumMoo671.jpg "title=" A.png " alt= "Wkiol1rbfwxyknztaaljspummoo671.jpg"/>


Permissions are added to everyone: Because you want to publish the site out.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/4C/9C/wKiom1RBFXiATU8GAAOHAlSnFd8133.jpg "title=" 2.PNG " alt= "Wkiom1rbfxiatu8gaaohalsnfd8133.jpg"/>


Add a default document of your own name, and move up to the top level if you don't have a name changed.


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/4C/9D/wKioL1RBFgXhHqr_AAH2jr3RD1I186.jpg "title=" S.png " alt= "Wkiol1rbfgxhhqr_aah2jr3rd1i186.jpg"/>

A computer with 4G memory can only open two virtual machines. So DNS is also on this server.

The DNS server address is also: 202.168.1.10


650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/4C/9C/wKiom1RBFfbhVjD3AAJr8DjTJGs963.jpg "title=" SS. PNG "alt=" Wkiom1rbffbhvjd3aajr8djtjgs963.jpg "/>

After the DNS settings are complete, test it with Nslookup in this machine 、、、、

Then configure the client:

Client DNS pointing to the server

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/4C/9D/wKioL1RBFoaTjUwsAAQkb5Bz-Sw751.jpg "title=" capture. PNG "alt=" Wkiol1rbfoatjuwsaaqkb5bz-sw751.jpg "/>

After you configure the basic command for the ASA, the ping package is not returned. But visiting the website is no problem. Because ICMP is stateless. The ASA is not logged.

HTTP high to low OK.

Client.. Test success:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/4C/9D/wKioL1RBFxyiTrT7AAJDZ-9s4a8892.jpg "style=" float: none; "title=" 12.PNG "alt=" Wkiol1rbfxyitrt7aajdz-9s4a8892.jpg "/>

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/4C/9C/wKiom1RBFubgt8FPAAK8pB1W39I333.jpg "style=" float: none; "Title=" captures ff. PNG "alt=" Wkiom1rbfubgt8fpaak8pb1w39i333.jpg "/>

Then configure URL filtering on the ASA:

Specific steps and explanations:

Asa:

Config T

Access-list tcp_filter Permit tcp 192.168.1.0 255.255.255.0 any eq www

Locate the source to reach any website traffic. Unable to locate accurately

Class-map Tcp_filter_class

Match Access-list Tcp_filter

/Match the class map of the source to reach all the web traffic

Exit



Class-map type Inspect HTTP Http_url_class

/definition Detection Class Http_url_class HTTP traffic that matches URLs in HTTP headers that do not contain Url_class class expressions

Match not request header host Regex class Url_class

The whitelist mechanism not request indicates that mismatches will be discarded and not represented by the blacklist, and the match will be dropped

Exit


Regex url1 "\.cisco\.com"

Match the regular expression match URL in the URL address (URL list) that carries the. cisco.com.

Class-map type regex match-any Url_class

Creates a collection of URLs. Multiple URL lists can be placed inside

Match Regex URL1

Exit


Policy-map type Inspect HTTP http_url_policy

Class Http_url_class

Drop-connection Log

Defines the rule detection class. Make the appropriate action to match or match the previous process

(drop)

Exit

Exit




Policy-map Inside_http_url_policy

Class Tcp_filter_class

Inspect HTTP Http_url_policy

Define Policy-map Inside_http_url_policy, define the results of the above rules and traffic detection into a policy container (POLICY-MAP)

Exit

Exit


Service-policy Inside_http_url_policy interface Inside

Apply the Policy-map to the interface to make it effective.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/4C/9D/wKioL1RBF4TQz9aoAAJDZ-9s4a8794.jpg "style=" float: none; "title=" 12.PNG "alt=" Wkiol1rbf4tqz9aoaajdz-9s4a8794.jpg "/>

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/4C/9C/wKiom1RBF0-AP1_cAAOQDXMpC-Q730.jpg "style=" float: none; "title=" 123.PNG "alt=" Wkiom1rbf0-ap1_caaoqdxmpc-q730.jpg "/>

All right.. Our experiment was done ... may not be very comprehensive ...

This article from the "heartbroken people in the Tianya" blog, declined reproduced!

The ASA firewall configures URL filtering. Detailed experimental steps

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.