Solved

Adding Domain Name and Sub Domain to Rule Exceptions on Cisco ASA 5585

Posted on 2013-10-25
1
1,813 Views
Last Modified: 2013-12-09
Having the DNS enabled on the Cisco ASA 5585 Firewall and attempting to add entire domain to exclusions.  The provided exclusions for the domain comes back as *.domain.com.

Cisco is requiring a FQDN to be added.  The vendor is/will not provide the actual IP address ranges.

How can I put the domain plus subdomains into exclusions rules for the ASA?
0
Comment
Question by:PSERS
1 Comment
 
LVL 7

Accepted Solution

by:
HalldorG earned 500 total points
ID: 39602510
You may use an alternative method specially if this is url filtering you want to solve.

Look at
https://supportforums.cisco.com/docs/DOC-1268

It is using regular expressions to match names in the http protocol.

Notice that names are not included in tcp header therfore you can not use wildcard in acl rules as there are countless possibilities of names that could be looked up. That might fit the ip address.  Also blocking based on dns names is not a good idea as the server may be serving other websites you want to access, which have the same ip address.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now