[c-nsp] Filtering traffic to destinations based off ofDNSaddresses on an ASA?

Nick Hilliard nick at foobar.org
Thu Feb 9 15:04:46 EST 2012


On 09/02/2012 18:26, Steve McCrory wrote:
> It depends on how you structure your regex but the format we used seemed
> pretty effective at blocking all traffic destined for those domains

It will certainly block http, but what about https?  The popular sites
mentioned (e.g. *.google.com, www.youtube.com, *.facebook.com) all support
https.

Nick



More information about the cisco-nsp mailing list