0% found this document useful (0 votes)
2 views41 pages

Cisco Cloud Web Security Overview

The document provides an overview of Cisco Cloud Web Security (CWS), detailing its features, functionality, and implementation processes. It covers aspects such as URL filtering, application visibility, traffic redirection, and the configuration of Cisco ASA and AnyConnect web security modules. Additionally, it discusses web filtering policies and verification methods within Cisco ScanCenter, emphasizing the importance of security in web traffic management.

Uploaded by

tojy.m12
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views41 pages

Cisco Cloud Web Security Overview

The document provides an overview of Cisco Cloud Web Security (CWS), detailing its features, functionality, and implementation processes. It covers aspects such as URL filtering, application visibility, traffic redirection, and the configuration of Cisco ASA and AnyConnect web security modules. Additionally, it discusses web filtering policies and verification methods within Cisco ScanCenter, emphasizing the importance of security in web traffic management.

Uploaded by

tojy.m12
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

[Link].

sa
Advanced Technologies in
Networks Security

Prepared By: NOUF HAMAD


Cloud Web Security
This lesson covers the following topics:
• Cisco Cloud Web Security (CWS)
• Describe the features and functionality
• Implement the IOS and ASA connectors
• Implement the Cisco AnyConnect web security module
• Describe the web filtering policy in cisco ScanCenter
Cisco Cloud Web Security (CWS)
Cloud Web Security

Cloud Web Security is located in the Internet edge


What is a CWS ?
CLOUD WEB SECURITY

What is the definition or description of the CWS :


It is a server that works in the cloud, and this server is with Cisco. Here, we either buy a
device WSA or we replace the device by buying a license for the Cloud Web Security.

Cloud WEB SECURITY is in the form of:


CWS can be added as a server inside the ASA, inside a router, inside WebSecurity a Planes,
or as a device.
Cisco Cloud Web Security Overview:
• Cisco CWS provedes scanning of HTTP and decrypted HTTPS traffic and malware protection.
• User HTTP and HTTPS traffic is redirected to the Cisco CWS.
• CWS utilizes data centers geographically Spread all over the world.
• CWS can be integrated with the Cisco adaptive security appliance, ISR G2 ,Web security appliance,
or AnyConnect Secure Mobility Client.
Cisco Cloud Web Security Traffic Flow Overview:
• User which is located behind the firewall makes the web request.
• The Cisco ASA Checks its service policies and if compliant,redirects traffic to ScanSave.
• ScanSave First ensures that the request is a permitted And valid web request and not an outbound
malware
• ScanSave then checks the validity of request against its policies.
• Traffic which is allowed is forwarded to the desired destination in Internet and traffic from web
site Is returned to ScanSave
• the received content is now scanned thoroughly for viruses and other malware.
Describe the features and functionality
Describe the features and functionality

• URL Filtering:
URL database covering over 50 million site worldwide,
Real time dynamic categorization for unknown URLs.

• Application visibility and control:


deep application control for social networking, file sharing
[Link], media and more.

• Reporting:
business intelligence tool provides best of class
reporting from the cloud, Full flexibility for analysis of
web usage and investigations.
Implement the IOS and ASA connectors
Cisco Cloud Web security traffic redirection overview:
Authentication key generation from
the Cisco ScanCenter.

If the company have a Cloud Web Security license, then I have to do active this license by going to the:
ScanCenter Admin > Authentication >Compnay key

Then entered the kay which cisco gave to the company i work for until I get to CWS.
Verifying traffic redirection to CWS
using special URL.

• These outputs indicate that any traffic coming from me


will be redirected to CWS.

• If I don't see these outputs, it means that the traffic is out


directly to the Internet without going through CWS
Cisco ASA Cloud Web security overview.

An enterprise that has a Cisco ASA in its network can use Cisco CWS services
without installing additional hardware.

We need to define ASA is that every time it goes to the Internet, it must take the traffic of the user
and send it to the CWS, and CWS will filter the traffic, and then either allow the traffic or not allow.
Cisco ASA Cloud Web security overview.

Configuration >Device Management >Cloud Web Security.


The first step:
• is to write your IP address for the CWS
• Enter the kay that Cisco will generate for me
Cisco ASA Cloud Web security overview (CONT)

Configuration> firewall > service policy rule >add > global policy.
The second step :
• is to go inside the ASA and create a new rule in the Policy.
and the rule must be Anyone out from my network it must pass through to CWS
Cisco ASA Cloud Web security overview (CONT)

The third step:


is to put the Traffic Class name here, then click Next.
Cisco ASA Cloud Web security overview (CONT)

Go to the : Rule action > protocol inspection > and then activation the CWS.
Verifying Cisco ASA cloud Web security
operations using the Cisco ASDM.

ASDM > Monitor> CWS.


Implement the Cisco AnyConnect web
security module
Cisco any connect Web Security Module for
Standalone Use Overview.
1- Download the Cisco Anyconnect Secure Mobility Client from Cisco ScanCentre .
2- Extract it in a new folder
3- Install The standalone Anyconnect Profile Editor with the Web Security Profile Editor enabled
4- use the Anyconnect Web Security Profile Editor to create a Web security XML Profile.

Make sure only the Anyconnect Web Security check box is checked.

What does mean Anyconnect ?


It is installed on the user device. So that every time I enter the site
via the VPN, I open Cisco AnyConnect then Type the address of
the site and then make connect
Configure Cisco Anyconnect Web security
module for standalone use.

Any connect Web Security Profile Editor-Scanning Proxy Settings.


• I download the program AnyConnect Scanning proxy
• Then I add to it the address of the Cloud Web Security, which I want to go to.
Configure Cisco Anyconnect Web security
module for standalone use.

Any connect Web Security Profile Editor-Scanning Proxy Settings.


• I write here the addresses of the sites that I want to go to directly without pass throu to the CWS
Configure Cisco Anyconnect Web security
module for standalone use.

Any connect Web Security Profile Editor-Scanning Proxy Settings.


• Enter authentication Key obtained from the Cisco ScanCenter.
Configure Cisco Anyconnect Web security
module for standalone use.

Any connect Web Security Profile Editor-Scanning Proxy Settings.


• Configure fail behavior if a connection to the Cisco CWS proxy server cannot be established.
Verifying Cisco Anyconnect Web Security
Module operation.

Cisco Anyconnect Secure Mobility Client > Web Security >Statistic


• Here is the license CWS
Describe the web filtering policy in cisco
ScanCenter
ScanCenter Web Filtering Policy Overview

Web filter > management > Policy.


Example of a rule nameed "test rule " with the block rule action.

This rule is applied to anyone (no group selected) at anytime using the "default" filter.
ScanCenter Web Filtering Policy Configuration

Web filter > management > filter > create filter.


ScanCenter Web Filtering Policy Configuration
ScanCenter Web Filtering Policy Configuration

Management > Policy >create rule.


ScanCenter Web Filtering Policy Configuration

• With this feature "Define filter" I active the filter that I created.
• Then I choose the time in which I apply the filter, either I choose a specific time or I
choose any time.
ScanCenter Web Filtering Policy Configuration

If I want to know what is the rules you created:


Web filtering> management> policy> manage policy.
ScanCenter Web Filtering Verification.

Verification of the results of web filtering :


results of search engine show sites which are filtered.
ScanCenter Web Filtering Verification.

Notification that user receives if try to access a blocked site.


Reason:This is in the category of Gambling , and the rule is inside the CWS and
this rule is allowed to block the site.
ScanCenter Web Filtering Verification.

The exclamation mark :means that the site is not blocked, but beware of it
because it is possible I being to attacked
ScanCenter Web Filtering Verification.

Use policy trace to ensure that the filtering settings are being applied as intended.
ScanCenter Web Filtering Verification.

How is the CWS knows that this site is one of the sites that is
forbidden to enter it?

The cloud web security :which is a server from Cisco that has updates for all
sites, and cloud web Security can acseess to 50,000,000 sites and know the
classification of each one of them.
Resource

BOOK : Implementing Cisco ThreatControl Solutions(SITCS)

You might also like