<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using wildcard in URL filtering in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/4468063#M1083758</link>
    <description>&lt;P&gt;In FDM, all sub-websites match by just using the base domain name.&lt;/P&gt;&lt;P&gt;Therefore, just enter &lt;STRONG&gt;microsoft.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Do not include an asterisk (i.e. &lt;STRONG&gt;*.microsoft.com&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;Do not include a dot (i.e. &lt;STRONG&gt;.microsoft.com&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will match microsoft.com, abc.microsoft.com, and abc.update.microsoft.com&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, notmicrosoft.com will not match&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been testing this successfully. Here's the reference:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-objects.html#task_49CC5243743F4921AAF00CF6AB0264BE" target="_blank" rel="noopener"&gt;Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager, Version 6.2.3 - Objects [Cisco Firepower NGFW] - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Look under &lt;EM&gt;Configuring URL Objects and Groups&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using version 7.0.0.1 with FDM, I don't know if previous 6.x versions worked the same way.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Sep 2021 22:59:02 GMT</pubDate>
    <dc:creator>bcoverstone</dc:creator>
    <dc:date>2021-09-16T22:59:02Z</dc:date>
    <item>
      <title>Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3196891#M929411</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can i block all connections to *.microsoft.com (for example)?&lt;/P&gt;
&lt;P&gt;Can i use custom URL object *.microsoft.com or firepower doesnt support wildcards?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3196891#M929411</guid>
      <dc:creator>lyutov_dv</dc:creator>
      <dc:date>2020-02-21T14:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197013#M929412</link>
      <description>&lt;P&gt;Firepower support wilcards in URL objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the screenshot below taken from my FMC 6.2.2:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FMC URL object with wildcard.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/1837i6C852C97ACE7ADD2/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMC URL object with wildcard.PNG" alt="FMC URL object with wildcard.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 11:56:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197013#M929412</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-11T11:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197015#M929413</link>
      <description>I can create an object but it doesn't work in access rules</description>
      <pubDate>Wed, 11 Oct 2017 11:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197015#M929413</guid>
      <dc:creator>lyutov_dv</dc:creator>
      <dc:date>2017-10-11T11:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197062#M929414</link>
      <description>I remember not long ago opened a cisco tac with similar issue. and TAC advise to use a WSA. according to them FMC/Firepower sensor do not support wild card in URL filtering.</description>
      <pubDate>Wed, 11 Oct 2017 12:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197062#M929414</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2017-10-11T12:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197064#M929415</link>
      <description>&lt;P&gt;Sorry about that&amp;nbsp; - you are correct. I found a technote mentioning this as well:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118852-technote-firesight-00.html#anc14" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118852-technote-firesight-00.html#anc14&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested on my FMC just now and found the same. However if I instead use microsoft.com instead of *.microsoft.com as my url object it works due to substring matching as described in the technote.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 12:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197064#M929415</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-11T12:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197071#M929416</link>
      <description>Yes I found this technote...&lt;BR /&gt;&lt;BR /&gt;it works but it's not the same because for example oldmicrosoft.com will be blocked as well, but it's another domain&lt;BR /&gt;</description>
      <pubDate>Wed, 11 Oct 2017 13:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197071#M929416</guid>
      <dc:creator>lyutov_dv</dc:creator>
      <dc:date>2017-10-11T13:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197075#M929417</link>
      <description>&lt;P&gt;Quite true - that is a limitation of the current platform.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will remember to bring this up with the Cisco engineers at next week's Security team event.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 13:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3197075#M929417</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-11T13:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3335509#M929418</link>
      <description>&lt;P&gt;So, what was the resolution to this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a URL blacklist, with, as an example, 777.com in it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;777.com blocks, but &lt;A href="http://www.777.com" target="_blank"&gt;www.777.com&lt;/A&gt; does not.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 23:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3335509#M929418</guid>
      <dc:creator>brian.emil.harris</dc:creator>
      <dc:date>2018-02-21T23:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3335969#M929419</link>
      <description>&lt;P&gt;So, it appears the substring matching works if I create an actual URL object, then block it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Substring matching, however, does not work, when populating a blacklist/whitelist in the Security Intelligence URL Lists and Feeds.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 15:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3335969#M929419</guid>
      <dc:creator>brian.emil.harris</dc:creator>
      <dc:date>2018-02-22T15:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3361953#M929420</link>
      <description>&lt;P&gt;This document might be helpful &lt;A title="FTD URL Filtering - How it works?" href="https://supportforums.cisco.com/t5/firepower-documents/ftd-url-filtering-how-it-works/ta-p/3347292" target="_self"&gt;FTD URL Filtering - How it works?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 17:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3361953#M929420</guid>
      <dc:creator>John Ventura</dc:creator>
      <dc:date>2018-04-06T17:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3679541#M929421</link>
      <description>&lt;P&gt;what came of this. &lt;BR /&gt;IF Firepower can not process wildcard, why does the product allow them to be created. Surely its not that hard to detect a wildcard and not save it and put up a screen that advises so?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 21:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/3679541#M929421</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2018-08-01T21:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/4276928#M1077547</link>
      <description>&lt;P&gt;Firepower does support wildcard, but not this format like&amp;nbsp; (*.microsoft.com) rather it support (.microsoft.com) format. You can create a URL object with value (.microsoft.com) for blocking all microsoft.com domain, it will block for support.microsoft.com/ &lt;A href="http://www.update.microsoft.com/&amp;nbsp;" target="_blank"&gt;www.update.microsoft.com/&amp;nbsp;&lt;/A&gt; or&amp;nbsp;any&amp;nbsp;other sub domain after .microsoft.com. So use dot(.) instead of asterisk(*) it will work fine. I am testing it in production environment.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 18:09:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/4276928#M1077547</guid>
      <dc:creator>Rokib Hasan</dc:creator>
      <dc:date>2021-01-21T18:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Using wildcard in URL filtering</title>
      <link>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/4468063#M1083758</link>
      <description>&lt;P&gt;In FDM, all sub-websites match by just using the base domain name.&lt;/P&gt;&lt;P&gt;Therefore, just enter &lt;STRONG&gt;microsoft.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Do not include an asterisk (i.e. &lt;STRONG&gt;*.microsoft.com&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;Do not include a dot (i.e. &lt;STRONG&gt;.microsoft.com&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will match microsoft.com, abc.microsoft.com, and abc.update.microsoft.com&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, notmicrosoft.com will not match&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been testing this successfully. Here's the reference:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-objects.html#task_49CC5243743F4921AAF00CF6AB0264BE" target="_blank" rel="noopener"&gt;Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager, Version 6.2.3 - Objects [Cisco Firepower NGFW] - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Look under &lt;EM&gt;Configuring URL Objects and Groups&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using version 7.0.0.1 with FDM, I don't know if previous 6.x versions worked the same way.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 22:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wildcard-in-url-filtering/m-p/4468063#M1083758</guid>
      <dc:creator>bcoverstone</dc:creator>
      <dc:date>2021-09-16T22:59:02Z</dc:date>
    </item>
  </channel>
</rss>

