Solved

Configure website filtering on Cisco router

Posted on 2008-10-02
14
1,589 Views
Last Modified: 2009-11-18
Need help in setting up the Cisco router to block websites.
Need to block facebook, craigslist, myspace, etc.

I tried the URL filtering but when i enable it, it blocks all websites. (weird)
and after i enable it, it asks me to add "any any port on the ACL" (dont know how to do that)

dont know much about Cisco, so it would be great if i get full instructions on setting this up.

thanks in advance.
0
Comment
Question by:andrew_transparent
  • 5
  • 5
  • 2
  • +1
14 Comments
 
LVL 4

Expert Comment

by:damalano
ID: 22627053
only thing i know ( but never used ) is explained here :

http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/

Hope it helps
0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22627103
ummm i dont think i have that network setup.
and that's REALLLLY complicated.

is there like a easy way, like normal routers have? just add the website to be blocked and your set?

tnx
0
 
LVL 4

Expert Comment

by:damalano
ID: 22627241
not that i know of sorry .
Maybe someone else.
0
 
LVL 6

Expert Comment

by:ajeab
ID: 22643543
If I'm not wrong, URL filter require addition purchase. (websense to be exact).
you can try to static set the dns address if you do your own DNS server (big job).
What I did with the place I work is to setup proxy server using DanGardian (free) and turn the category on from there.
0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22652492
i dont think you have to purchase it. or maybe im wrong?
i see it on the Firewall policies --> Application Security when using SDM

i just want to know how to set this up properly.
because as i was saying.. when i enable URL filtering it blocks all the websites.

tnx.
0
 
LVL 4

Expert Comment

by:damalano
ID: 22652778
Hey andrew,

I'm note sure if you have to buy websense as ajeab said. ( could be i could find it.
Here's how to configure. ( i haven't tried it but maybe you can ) Tell me if it works i'd like to know too ( i do'nt have an testing setup )

http://www.cisco.com/en/US/docs/ios/12_2t/12_2t15/feature/guide/ftwebsen.html
0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22655346
wow..that looks complicated.
i dont have a test setup too...im doing this LIVE ..yikes.


0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 1

Author Comment

by:andrew_transparent
ID: 22655350
where's Jfrederick29???

i think he'll know a better way.hmmm
0
 
LVL 4

Expert Comment

by:damalano
ID: 22656691
ok you wait for Jfrederick29

Good Luck
0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22660460
is he seeing this question?
i asked him on the last question he answered for me to help me with this one too....

helppp :-(
0
 
LVL 4

Expert Comment

by:damalano
ID: 22660952
If you are looking for a one click install maybe you should not use cisco.
Cisco is and will always be a major part working in CLI. If this is too complicated for you maybe you should setup an isa server. That is more clickerdieclick. I hope Jfrederick29 did not see the question for you or else he doensn't know the one click answer too like me. And i know he's good !

My last link is not that complicated. i don't think you would find an easier solution. just backup your config and and folow the step-by-step instruction. If it does'nt accept an command it is probably not supported by your system. you need  at least 12.2(15)T .

If it fails restore your config and nothing happend.

Good luck again !

0
 
LVL 6

Accepted Solution

by:
ajeab earned 500 total points
ID: 22661374
websense that embed in cisco is part of websense enterprise.  the sample price here
http://www.securehq.com/group.wml&deptid=45&groupid=225&sessionid=200810712541217293
no way that websense or h2n2 will give it for free.  

I agree with damalano here.  Cisco is not plug-n-play device.  it's require some knowledge to set it up.  the last link is a step-by-step instruction.

if you want to use something easy, I did use a product call IBOSS from http://www.iphantom.com at one of my site.  It require subscription (but much cheaper than websense) . The device sit between your router and your modem.  it work similar to DanGardian but without computer.  There are different category for you to turn on/off to filter.  

hope this help
0
 

Expert Comment

by:ajay2801
ID: 23372119
just use the WCCP and configure your router to redirect all you traffc to websense and then apply all the policies in the websense.
It will workd.

0
 

Expert Comment

by:ajay2801
ID: 23372146
If you dont' want to use the Websens and do this on the router basis then use the QoS.
Use the class map to permit and deny the website and then call this class map in the policy map.

Then apply the policy map on the interface.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now