
3-34
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 3 Controlling Network Access and Use
Filtering Outbound Connections
Buffering HTTP Replies for Filtered URLs
By default, when a user issues a request to connect to a specific website, the PIX Firewall sends the
request to the web server and to the filtering server at the same time. If the filtering server does not
respond before the web content server, the response from the web server is dropped. This delays the web
server response from the point of view of the web client.
By enabling the HTTP response buffer, replies from web content servers are buffered and the responses
will be forwarded to the requesting user if the filtering server allows the connection. This prevents the
delay that may otherwise occur.
To enable the HTTP response buffer, enter the following command:
url-block block block-buffer-limit
Replace block-buffer-limit with the maximum number of blocks that will be buffered. The permitted
values are from 0 to 128, which specifies the number of 1550-byte blocks that can be buffered at one
time.
Filtering Long URLs with the Websense Filtering Server
Note PIX Firewall Versions 6.2 and higher support a fixed, maximum URL length of 1159 bytes for the N2H2
filtering server.
To increase the maximum length of a single URL that can be sent to a Websense filtering server, enter
the following command:
url-block url-size long-url-size
Replace long-url-size with a value from 2 to 4 for a maximum URL size of 2 KB to 4 KB.
To configure the maximum memory available for buffering long URLs, enter the following command:
url-block url-mempool memory-pool-size
Replace memory-pool-size with a value from 2 to 10240 for a maximum memory allocation of 2 KB to
10 MB.
Filtering HTTPS and FTP Sites
PIX Firewall Version 6.3 introduces support for filtering of HTTPS and FTP sites for Websense filtering
servers.
Note HTTPS and FTP filtering are not supported for the N2H2 filtering server.
HTTPS filtering works by preventing the completion of SSL connection negotiation if the site is not
allowed. The browser displays an error message such as “The Page or the content cannot be displayed.”
Because HTTPS content is encrypted, PIX Firewall sends the URL lookup without directory and
filename information.
Commentaires sur ces manuels