Configuring Web Type ACLs

Cisco ASA enables network administrators to further their clientless SSL VPN security by configuring web-type access control lists (ACL) to manage access to web, Telnet, SSH, citrix, FTP, file, e-mail servers, or all types of traffic. These ACLs affect only the clientless SSL VPN traffic and are processed in sequential order until a match is found. If an ACL is defined but no match exists, the default behavior on the security appliance is to drop the packets. On the other hand, if no web-type ACL is defined, Cisco ASA allows all traffic to pass through it.

Moreover, this robust SSL VPN feature allows these ACLs to be downloaded from a Cisco Secure Access Control Server (CS-ACS) by using vendor-specific attributes (VSA). This allows central control and management of user access into the corporate network by offloading ACL definitions locally on the security appliance.

TIP Using CS-ACS, a web-type ACL can be configured by specifying the webvpn:inacl# prefix in the downloadable ACLs, where # indicates the sequence number of an access control entry (ACE).

A web-type ACL is configured by choosing Configuration > Remote Access VPN > Clientless SSL VPN Access > Advanced > Web ACLs. Click Add and select Add ACL to define a new web-type ACL. Specify a web ACL name and click OK. Select the newly created ACL name, click Add again, and select Add ACE. You have two options to add a web-type ACL:

• Filter on URL: A URL-based web ACL is used to filter out SSL VPN packets if they contain a URL such as http://.

• Filter on address and service: An address- and service-based web ACL is used to filter out SSL VPN packets if they use TCP encapsulation based on the IP address and a Layer 4 port number.

If you prefer to add a URL-based entry to filter out SSL VPN traffic, select Filter on URL and select the protocol you want to filter. The security appliance allows you to filter based on cifs, citrix, citrixs, ftp, http, https, imap4, nfs, pop3, smart tunnel, smtp, ssh, and telnet for all types of URLs. Next, specify the URL or a wildcard to filter traffic. For example, if you want all clientless users to deny web traffic to internal.securemeinc.com, select Deny as the Action, choose http as the filter protocol, and select internal.securemeinc.com as the URL entry. This is illustrated in Figure 5-31. Click OK when finished.

If you want to include all URLs that are not explicitly matched in the ACL, you can include an asterisk (*) as a wildcard. For example, to block POP3 e-mail access and allow all other protocols, perform the following steps:

• Add an ACE and deny POP3 for the protocol and add * as a wildcard URL entry.

• Add another ACE and allow any for the protocol type.

If you would rather permit or block TCP traffic that is destined to particular addresses on specific ports, choose the Filter on Address and Service option. For example, to block all clientless traffic destined to 192.168.0.0/16 on port 23, select Deny as the Action, specify 192.168.0.0/16 under Address, and choose 23 under Service. Click OK when finished.

Figure 5-31 Defining Web-Type ACLs r cisco

Notwk(Cfcii) At neu

Ö] Pvst Cwimliuii Pid in pbDUpPctdei

(vyivarfc; atxovk pi a im fei E3 flnyt-omect Lostcrirat." vi ay aii+ihi aisky'fnrrt W Adraud z Pg C"W*Vsb <i<aW« fif rm PJCijin-ljjiPidic.

g^iVm^Ptiim

LVriarrt: Access Fckw a IgAAwriïri

^gPwmyBflWK

^Pwrinv

EÏ Java Code 3gner

Curtail C«Jw ^Content Rewrite pApfi-^nHrip«'

ygnco jervtf:

Mi flpmoiu a«ws vrtj

J lievKo Mam»iB"iw<

Configuration > Remote Access VPN > Cfcemless SSL VPN Access > Advanced > Wei) ACLs fF* QMK| * * I jt * A 'I

cisco

Configuration > Remote Access VPN > Cfcemless SSL VPN Access > Advanced > Wei) ACLs fF* QMK| * * I jt * A 'I

œ 1

MfcKA [ SoofcB

Aittai

Tins 1 Lwn)

nmtrttÂffèrdrliiK

XI

iVhnfi: C Pcm« <• Deny

titer on IV.L

|http jrj :ll iHwnal.îeoremrt-K.c

( Filer Mi otMrHi nd swvfco

tviirr\'.: [

J

Ssrvfcäi 1

J

Lo«W -

P matte LcitjTfl

Low*} Level: |>faJt

Mure Dptiui 1»

CK 1 CsitBi 1

When you define an ACE that has deny as its first entry, make sure that you configure another entry to permit all other clientless SSL VPN traffic.

After a web ACL is configured, link it to a default user group or user policy. Choose Configuration > Remote Access VPN > Clientless SSL VPN Access > Group Policies > ClientlessGroupPolicy > Edit > General and select the WebACL list on the Web VPN drop-down menu.

CAUTION

Web ACLs do not block a user from accessing the resources outside the SSL VPN tunnel. These ACLs ensure that SSL VPN traffic denied by the ACLs will not pass through the security appliance.

Continue reading here: Configuring Smart Tunnels

Was this article helpful?

0 -1