?
Solved

Adding Domain Name and Sub Domain to Rule Exceptions on Cisco ASA 5585

Posted on 2013-10-25
1
Medium Priority
?
2,822 Views
Last Modified: 2013-12-09
Having the DNS enabled on the Cisco ASA 5585 Firewall and attempting to add entire domain to exclusions.  The provided exclusions for the domain comes back as *.domain.com.

Cisco is requiring a FQDN to be added.  The vendor is/will not provide the actual IP address ranges.

How can I put the domain plus subdomains into exclusions rules for the ASA?
0
Comment
Question by:PSERS
1 Comment
 
LVL 7

Accepted Solution

by:
HalldorG earned 1500 total points
ID: 39602510
You may use an alternative method specially if this is url filtering you want to solve.

Look at
https://supportforums.cisco.com/docs/DOC-1268

It is using regular expressions to match names in the http protocol.

Notice that names are not included in tcp header therfore you can not use wildcard in acl rules as there are countless possibilities of names that could be looked up. That might fit the ip address.  Also blocking based on dns names is not a good idea as the server may be serving other websites you want to access, which have the same ip address.
0

Featured Post

The new generation of project management tools

With monday.com’s project management tool, you can see what everyone on your team is working in a single glance. Its intuitive dashboards are customizable, so you can create systems that work for you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

601 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question