Solved

URL filtering

Posted on 2007-11-28
2
649 Views
Last Modified: 2012-05-05
We would like to allow the VPN users that come through our 2 Cisco ASA's to be limited to a handful of Internet sites.  What is the best (and easiest) way to accomplish this?  Can the solution be different by user or by ASA or is standard for all users?  We don't necessarily need this for our network users, but may in the future include desktop pc's to use this solution also.  Any advice is greatly appreciated.  Thanks!!
0
Comment
Question by:turtletrax
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
ID: 20441973
>>What is the best (and easiest) way to accomplish this?

Best and easiest don't always go together...;)

However, if you want my opinion on best, you have to use a 3rd party filtering application or appliance.  I've used Websense in the past and it works well.  It has a lot of granularity with its settings (you can impose quotas where you determine how long a user can surf sites that are typically blocked by using their quota time, you can have different policies be in effect at different times of day and on business days only, weekends only or any combination you can think of, etc.)  It integrates with Windows NT domains or AD domains, Java System Directory Server and Novell NDS, which answers your question about it being able to be implemented on a per user basis.  Most definitely, or it can be implemented on a group basis, such as AD user groups.

Some have considered Websense the "Cadillac" of the content filtering solutions, but it's what I've used and one that I can recommend.

However, the point is that you will need a 3rd party component to do content filtering with since the ASA cannot do it by itself.
0
 

Author Comment

by:turtletrax
ID: 20443761
Thanks, you were exactly right about needing a 3rd party application/appliance.  I found I couldn't do what I needed to do unless I had something else.  We are going to try a Barracuda web filtering appliance.  We are expecting delivery of it any day so once we have it in place I will report back to let everyone know how we like it.  Thanks for your help.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA 5506 blocks telnet 11 66
QoS on Cisco router 10 60
Cisco ASA 5510 Question 3 47
Cisco L3 Switch - Show DHCP Server's IP Address for every VLAN 3 18
There are many useful and sometimes not well documented or forgotten IOS or ASA/PIX commands. See IPE article here , there was also one on PacketU and on Cisco Tips & Tricks. Below are my favorites. I give also a few most often used for Cisco IPS an…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question