Solved

Cisco asax sourcefire Ips

Posted on 2016-07-19
7
69 Views
Last Modified: 2016-08-01
Hi,
i have a Cisco ASAx with sourcefire IPS.
I'am tryng to perform a rules for deny a particular url like http://www.myname.com/etc/etc.

Is this possible or i need URL filtering license ?
Thank you.
Mauro
0
Comment
Question by:Pelitti
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 14

Accepted Solution

by:
SIM50 earned 500 total points
ID: 41719159
You can block it without URL filtering license. URL filtering license is needed for reputation and category based rules.
0
 

Author Comment

by:Pelitti
ID: 41719167
Thank you.

Does anyone already try this?

Thank you.
Mauro
0
 
LVL 9

Expert Comment

by:Ian Arakel
ID: 41722293
Hi there,

Is the setup integrated with and AD for user based access?
0
Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

 
LVL 57

Expert Comment

by:Pete Long
ID: 41737352
how you do this depends on whether you are using the FMC aplliance or managing the SFR module directly from the ASDM?

If it's the latter, see this article ASA 5506-X / 5508-X Setup FirePOWER Services (for ASDM)

Scroll down to 'Blocking a Particular URL with FirePOWER Services'

If you are using the FMC, Let me know, and I'll create a new article for that.

Regards,

Pete
1
 

Author Comment

by:Pelitti
ID: 41737364
Hi,
thank you.
I am using FMC, but i am able to perform the step.
I will like to perform this by a new rules.
What i need is something like: This url is ok if an ip address perform a request in a second, is not ok and i need to drop it if an ip address perform 8-10 request in 2 seconds.

Thank you.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 41737419
Ohh thats a good question! Is this just for one IP/group? Normally I'd do this will a Policy framework rather than the FirePower?

Pete
0
 

Author Comment

by:Pelitti
ID: 41737429
Maybe I should open a new question.
I would do this for any ip, not for a preset.

Best regards.
Mauro
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question