VMware NSX-T 3.2 Analyzing URL Traffic

FQDN Analysis allows administrators to gain insight into the type of websites accessed within the organization, and understand the reputation and risk of the accessed websites.

How to configure:

NSX-T URL Analysis landing page explaining north-south URL visibility and the need to assign a profile to an edge cluster.

Security > North South Security > URL Analysis

URL Analysis settings listing edge clusters before URL analysis is enabled.

You need to enable the service which is disabled by default

Highlight your edge and click enable

Confirmation dialog warning that enabling the feature starts URL analysis on the selected edge cluster.

Yes but only if you really mean it

URL Analysis status row showing data version 8.267.9 and the service in Up state.

Confirm the status is up – this can take a while

Next we will be creating Custom Context Profiles for URL Analysis

URL Analysis settings showing the TX-Prod edge cluster enabled and the control for assigning context profiles.

While remaining on the URL Analysis > Settings tab

Click Set under Profiles

Select Context Profile dialog for the edge cluster before any context profiles have been created.

Add Context Profile

Context-profile editor requesting a profile name and attributes for URL analysis.

Provide a name then click Set under Attributes

Set Attributes dialog for the URL analysis context profile before an attribute is added.

Add Attribute

URL analysis attribute selector with URL Category chosen as the attribute name.

URL Category

URL Category attribute dialog listing selectable categories such as health, finance, gambling, games, and entertainment.

I tend to select all options but you could just select what you are analyzing for

Context-profile attributes showing URL Category with Abortion and 82 additional categories selected.

Apply

Next we need to create a Gateway Firewall Rule for the T1 Router in our environment

NSX-T Gateway Firewall view for the TX-Prod Tier-1 gateway where the URL-analysis policy will be added.

+Add Policy

Then Provide the Policy a name

Gateway-specific firewall view with a new URL-analysis policy ready for its first rule.

Next we need to add a rule

Gateway Firewall policy menu with the Add Rule command and policy-placement options.

Add Rule

Unpublished gateway-firewall rule named URL Rule with Any source and fields for destinations, services, context profiles, scope, and action.

Give the Rule a name like URL Rule

Leave Sources as Any

Leave Destination as Any

Click services

Set Services dialog with DNS and DNS-UDP selected for the URL-analysis firewall rule.

Add DNS and DNS-UDP

Apply

Gateway-firewall rule row showing DNS services selected before a context profile is assigned.

Click the edit under Context Profiles

Context-profile selector showing the available profile for the URL-analysis gateway-firewall rule.

Select DNS then apply

Apply

Gateway-firewall rule row with DNS service, DNS context profile, Tier-1 scope, and Allow action configured.

Finally, leave the T1 default and allow as default.

VMware NSX-T firewall policy screen for publishing a URL traffic analysis.

Publish

Generate web traffic

Facebook login page opened from an internet-facing virtual machine to generate URL-analysis traffic.

Log into one of your internet facing virtual machines and go to different web pages.

Also, you can log into your Link Virtual machines and ping websites

URL Analysis dashboard showing 198 analyzed URLs with session counts, reputation distribution, and category distribution.

After waiting 5-15 minutes the URL Analysis should begin reporting

Now you can review reputation scores, the reputation and category distributions, etc.

Keep exploring

Choose your next step

Continue with the path that best matches the architecture or operating challenge in front of you.

Leave a Reply

Discover more from Digital Thought Disruption

Subscribe now to keep reading and get access to the full archive.

Continue reading