Solved

Prepare for egress filtering on Cisco ASA

Posted on 2014-12-19
3
293 Views
Last Modified: 2015-12-22
We currently have a Cisco ASA running software version 9.1.  We need to implement egress filtering.  I know some of the applications/ports that need to be allowed out of our network.  However, I don't want to implement egress filtering and block outbound traffic that I'm not aware of that is required for business.

Is there an easy way to find out what some of our traffic patterns are on the firewall so I can get an idea of what outbound ports might currently be used?
0
Comment
Question by:RickAstley
3 Comments
 
LVL 3

Expert Comment

by:vipelite
ID: 40509751
Just get a WebProxy and filter through that. You don't want to use ASA for web filtering. For inbound use ASA.
0
 
LVL 9

Accepted Solution

by:
Donboo earned 500 total points
ID: 40511588
On the ASA there is no easy way to do this. There are no monitoring mode on ACLs. if you want to know the traffic patterns without blocking i´d suggest you use CX or Firepower in monitoring mode.

An ACL with permit IP any any log sent to a syslog will probably generate too much info....
0
 

Expert Comment

by:FlatheadIT
ID: 41381574
You can monitor egress traffic using the syslog or you can setup a filter to watch outbound traffic - only for a very small organization (ASDM.)  However, without syslog this will be cumbersome.  

That said, if there are known sites you do not wish your users to hit, there are tools available to block malware (Botnet filter for one) and access to sites your organization deems unacceptable.  Here are some options in a CISCO environment:

Sourcefire will do this type of monitoring/blocking - as will PRSM - this is not easy with PRSM and it is even more cumbersome with an active/standby pair setup.  I have not used firepower (sourcefire) for this only PRSM.  But it works.  If you wish to take it one step further, setup CISCO CDA (this is an OVA vmware virtual appliance - formerly this was an AD agent) then you can setup AD groups with rules to block access to content by type and by url for AD groups - this comes in handy if you have a need for access to certain sites for Law enforcement etc.  that would be blocked for other departments in your organization.  *** Warning here - CISCO Licenses and modules may be required for this. ***  Make sure your vendor is aware of the licensing on CISCO.  It is often the case where the cost is not the hardware - it is the licensing and smartnet.
FYI end of life on PRSM is August 2018 - so don't go with PRSM - you should use sourcefire.  Lesson learned here.

You can also block outgoing traffic via IP from an ASA (For example - you wish to block the country of China - you can get the list of IP's in China, create a network object group, then use a a text file via cli or command line in ASDM (Multiple line) to place them in the firewall.  You can then add a rule to block outgoing traffic to those IP addresses (ingress and egress with rules on the firewall.)
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question