Block URLs using REGEX’s
object network CDS_Guest_BT_IP
description CHG0044382
host 86.162.16.160
!
! Define the websites we wish to block :
regex REG-URL2 “connect.o-sys.com/lp/CDS_Indy”
regex REG-URL3 “connect.o-sys.com/lp/CDS_Houston”
regex REG-URL4 “connect.o-sys.com/lp/BP”
!
! Set a class to match if the header has any of the URLs in it :
class-map type inspect http match-any CM-BLOCK-URL
match request header host regex REG-URL2
match request header host regex REG-URL3
match request header host regex REG-URL4
! Identify the ACL that will be subject to this inspection
access-list ACL-HTTP-INSPECT extended deny tcp object CDS_Guest_BT_IP object any eq http
! Set a class to match :
class-map CM-BLOCK-HTTP
match access-list ACL-HTTP-INSPECT
! Create a policy map to drop the connection if it matches the class map :
policy-map type inspect http PM-BLOCK-URL
parameters
class CM-BLOCK-URL
drop-connection log
! Apply the policy
policy-map global_policy
class CM-BLOCK-HTTP
inspect http PM-BLOCK-URL
! service-policy global_policy global
! Identify the 1 URL that will be permitted in :
regex REG-URL1 “connect.o-sys.com/lp/CDS”
! Create a class map to pass or permit the traffic if the URL isnt ANY of the regex’s
class-map type inspect http match-all CM-ALLOWED-URLS
match not request header host regex REG-URL1
! Identify the ACL that will be subject to this inspection
access-list ACL-HTTP-INSPECT extended permit tcp object CDS_Guest_BT_IP object any eq http
! Set a class to match :
class-map CM-ALLOW-HTTP
match access-list ACL-HTTP-INSPECT
! Create the policy map to drop any packets that passed the class map
policy-map type inspect http PM-ALLOW-HTTP
parameters
class CM-ALLOWED-URLS
drop-connection log
! Apply the Policy
policy-map global_policy
class CM-ALLOW-HTTP
inspect http PM-ALLOW-HTTP
! service-policy global_policy global
Comments
(There are currently no comments for this post.)