ASA URL Filter

1.创建class-map,识别传输流量

asa(config)#access-list tcp_filter1 permit tcp 192.168.201.0 255.255.255.240 any eq www
asa(config)#class-map tcp_filter_class1
asa(config-cmap)#match access-list tcp_filter1
asa(config-cmap)#exit
asa(config)#regex url1 \.sina\.com
asa(config)#class-map type regex match-any url_class1
asa(config-cmap)#match regex url1
asa(config-cmap)#exit
asa(config)#class-map tpye inspect http http_url_class1
asa(config-cmap)#match not request header host regex class url_class1
asa(config-cmap)#exit

2.创建policy-map,关联class-map

asa(config)#policy-map type inspect http http_url_policy1
asa(config-pmap)#class http_url_class1
asa(config-pmap-c)#drop-connection log
asa(config-pmap-c)#exit
asa(config-pmap)#exit

asa(config)#policy-map inside_http_url_policy
asa(config-pmap)#class tcp_filter_class1
asa(config-pmap-c)#inspect http http_url_policy1
asa(config-pmap-c)#exit
asa(config-pmap)#exit
 

3.应用policy-map到接口上

asa(config)#service-policy inside_http_url_policy interface inside

你可能感兴趣的:(职场,url,休闲,asa)