Solved

url filtering question on ASA?

Posted on 2010-11-26
8
465 Views
Last Modified: 2012-06-21
Hi Experts,

i came across this situation where in websense was configured for url filtering on the ASA and it had this command:

filter url ftp 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow

according to my understanding filter url is for http traffic but the above command points me to http traffic on port 21. is that correct?? if so what kind of traffic is it? and how does the websense deal with this or what will it look for?

i ask this coz in this scenario when some one does a http://ftp.xyz.com it does not allow access to this site. but when i remove this command everything is fine.

any help would be appreciated.

thx.
0
Comment
Question by:ullas_unni
  • 4
  • 4
8 Comments
 
LVL 20

Expert Comment

by:RPPreacher
ID: 34221580
This filters FTP connections from any source to any source.  Port 21.  Not HTTP.
0
 
LVL 4

Author Comment

by:ullas_unni
ID: 34221635
i thought that was done by the command

filter ftp 21 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
0
 
LVL 20

Accepted Solution

by:
RPPreacher earned 500 total points
ID: 34221839
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 
LVL 4

Author Comment

by:ullas_unni
ID: 34221972
i understand that port is optional but the doc says:

 'Replace port with the port number on which to filter HTTP traffic if a different port than the default port for HTTP (80) is used. In order to identify a range of port numbers, enter the start and end of the range separated by a hyphen.'

so how is it ftp traffic?
0
 
LVL 20

Expert Comment

by:RPPreacher
ID: 34222161
Because it is.  Because that is the command for filtering FTP.  Because it says "filter url FTP"

Because if you were going to filter HTTP, it would say "filter url HTTP"
0
 
LVL 4

Author Comment

by:ullas_unni
ID: 34222245
okay.. then does filter ftp 21 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow do the same functionality?
0
 
LVL 20

Expert Comment

by:RPPreacher
ID: 34222248
filter ftp is 6.x command
filter url ftp is 7.0 and 8.0 command
0
 
LVL 4

Author Comment

by:ullas_unni
ID: 34222252
you know what.. i think i got confused! i looked this up in the command reference tool and got the idea. anyways thx.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question