Solved

Configure website filtering on Cisco router

Posted on 2008-10-02
14
1,597 Views
Last Modified: 2009-11-18
Need help in setting up the Cisco router to block websites.
Need to block facebook, craigslist, myspace, etc.

I tried the URL filtering but when i enable it, it blocks all websites. (weird)
and after i enable it, it asks me to add "any any port on the ACL" (dont know how to do that)

dont know much about Cisco, so it would be great if i get full instructions on setting this up.

thanks in advance.
0
Comment
Question by:andrew_transparent
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
  • 2
  • +1
14 Comments
 
LVL 4

Expert Comment

by:damalano
ID: 22627053
only thing i know ( but never used ) is explained here :

http://ardenpackeer.com/qos-voip/tutorial-how-to-use-cisco-mqc-nbar-to-filter-websites-like-youtube/

Hope it helps
0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22627103
ummm i dont think i have that network setup.
and that's REALLLLY complicated.

is there like a easy way, like normal routers have? just add the website to be blocked and your set?

tnx
0
 
LVL 4

Expert Comment

by:damalano
ID: 22627241
not that i know of sorry .
Maybe someone else.
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 
LVL 6

Expert Comment

by:ajeab
ID: 22643543
If I'm not wrong, URL filter require addition purchase. (websense to be exact).
you can try to static set the dns address if you do your own DNS server (big job).
What I did with the place I work is to setup proxy server using DanGardian (free) and turn the category on from there.
0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22652492
i dont think you have to purchase it. or maybe im wrong?
i see it on the Firewall policies --> Application Security when using SDM

i just want to know how to set this up properly.
because as i was saying.. when i enable URL filtering it blocks all the websites.

tnx.
0
 
LVL 4

Expert Comment

by:damalano
ID: 22652778
Hey andrew,

I'm note sure if you have to buy websense as ajeab said. ( could be i could find it.
Here's how to configure. ( i haven't tried it but maybe you can ) Tell me if it works i'd like to know too ( i do'nt have an testing setup )

http://www.cisco.com/en/US/docs/ios/12_2t/12_2t15/feature/guide/ftwebsen.html
0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22655346
wow..that looks complicated.
i dont have a test setup too...im doing this LIVE ..yikes.


0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22655350
where's Jfrederick29???

i think he'll know a better way.hmmm
0
 
LVL 4

Expert Comment

by:damalano
ID: 22656691
ok you wait for Jfrederick29

Good Luck
0
 
LVL 1

Author Comment

by:andrew_transparent
ID: 22660460
is he seeing this question?
i asked him on the last question he answered for me to help me with this one too....

helppp :-(
0
 
LVL 4

Expert Comment

by:damalano
ID: 22660952
If you are looking for a one click install maybe you should not use cisco.
Cisco is and will always be a major part working in CLI. If this is too complicated for you maybe you should setup an isa server. That is more clickerdieclick. I hope Jfrederick29 did not see the question for you or else he doensn't know the one click answer too like me. And i know he's good !

My last link is not that complicated. i don't think you would find an easier solution. just backup your config and and folow the step-by-step instruction. If it does'nt accept an command it is probably not supported by your system. you need  at least 12.2(15)T .

If it fails restore your config and nothing happend.

Good luck again !

0
 
LVL 6

Accepted Solution

by:
ajeab earned 500 total points
ID: 22661374
websense that embed in cisco is part of websense enterprise.  the sample price here
http://www.securehq.com/group.wml&deptid=45&groupid=225&sessionid=200810712541217293
no way that websense or h2n2 will give it for free.  

I agree with damalano here.  Cisco is not plug-n-play device.  it's require some knowledge to set it up.  the last link is a step-by-step instruction.

if you want to use something easy, I did use a product call IBOSS from http://www.iphantom.com at one of my site.  It require subscription (but much cheaper than websense) . The device sit between your router and your modem.  it work similar to DanGardian but without computer.  There are different category for you to turn on/off to filter.  

hope this help
0
 

Expert Comment

by:ajay2801
ID: 23372119
just use the WCCP and configure your router to redirect all you traffc to websense and then apply all the policies in the websense.
It will workd.

0
 

Expert Comment

by:ajay2801
ID: 23372146
If you dont' want to use the Websens and do this on the router basis then use the QoS.
Use the class map to permit and deny the website and then call this class map in the policy map.

Then apply the policy map on the interface.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question