1-14
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Filtering Services
Filtering URLs and FTP Requests with an External Server
To enable HTTPS filtering, enter the following command:
Filtering FTP Requests
You must identify and enable the URL filtering server before enabling FTP filtering.
Note
Websense and Secure Computing Smartfilter currently support FTP; older versions of Secure Computing
SmartFilter (formerly known as N2H2) did not support FTP filtering.
When the filtering server approves an FTP connection request, the ASA allows the successful FTP return
code to reach the originating client. For example, a successful return code is “250: CWD command
successful.” If the filtering server denies the request, the FTP return code is changed to show that the
connection was denied. For example, the ASA changes code 250 to “550 Requested file is prohibited by
URL filtering policy.”
To enable FTP filtering, enter the following command:
Command
Purpose
filter https
port
[
-port
]
localIP
local_mask foreign_IP foreign_mask
[
allow
]
Example:
hostname# filter https 443 0 0 0 0 0 0 0 0
allow
Enables HTTPS filtering.
Replaces
port
[
-port
] with a range of port numbers if a different port than
the default port for HTTPS (443) is used.
Replaces
local_ip
and
local_mask
with the IP address and subnet mask of
a user or subnetwork making requests.
Replaces
foreign_ip
and
foreign_mask
with the IP address and subnet mask
of a server or subnetwork responding to requests.
The
allow
option causes the ASA to forward HTTPS traffic without
filtering when the primary filtering server is unavailable.
Command
Purpose
filter
ftp
port
[
-port
]
localIP local_mask
foreign_IP foreign_mask
[
allow
]
[
interact-block
]
Example:
hostname# filter ftp 21 0 0 0 0 0 0 0 0
allow
Enables FTP filtering.
Replaces
port
[
-port
] with a range of port numbers if a different port than
the default port for FTP (21) is used.
Replaces
local_ip
and
local_mask
with the IP address and subnet mask of
a user or subnetwork making requests.
Replaces
foreign_ip
and
foreign_mask
with the IP address and subnet mask
of a server or subnetwork responding to requests.
The
allow
option causes the ASA to forward HTTPS traffic without
filtering when the primary filtering server is unavailable.
Use the
interact-block
option to prevent interactive FTP sessions that do
not provide the entire directory path. An interactive FTP client allows you
to change directories without typing the entire path. For example, you
might enter
cd ./files
instead of
cd /public/files
.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......