<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD does not block sites based on URL rule in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925007#M1104309</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I got an issue with FTD filtering based on URL rules (predefined categories).&lt;/P&gt;&lt;P&gt;I have some rules that blocks sites with adult content, gambling, video games and other categories:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apasat_0-1695042753946.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197545i706EB2CB9478AF25/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apasat_0-1695042753946.png" alt="apasat_0-1695042753946.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some of sites are blocked and I got&amp;nbsp;&lt;SPAN&gt;ERR_CONNECTION_RESET, so it's working fine, but a lot of websites are still accessible, even if Connection Events says it's blocked based on ACP:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apasat_1-1695042861200.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197546iDA6BD39895BC59A6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apasat_1-1695042861200.png" alt="apasat_1-1695042861200.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I made a rule for this website in screenshot based on it's URL, but it's still working. After this, I banned it's IP addresses, and it stopped working (rule worked fine).&lt;/P&gt;&lt;P&gt;Can someone explain me why FTD does not block websites, but sends logs that it's blocking?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2023 13:25:17 GMT</pubDate>
    <dc:creator>apasat</dc:creator>
    <dc:date>2023-09-18T13:25:17Z</dc:date>
    <item>
      <title>FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925007#M1104309</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I got an issue with FTD filtering based on URL rules (predefined categories).&lt;/P&gt;&lt;P&gt;I have some rules that blocks sites with adult content, gambling, video games and other categories:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apasat_0-1695042753946.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197545i706EB2CB9478AF25/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apasat_0-1695042753946.png" alt="apasat_0-1695042753946.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some of sites are blocked and I got&amp;nbsp;&lt;SPAN&gt;ERR_CONNECTION_RESET, so it's working fine, but a lot of websites are still accessible, even if Connection Events says it's blocked based on ACP:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apasat_1-1695042861200.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197546iDA6BD39895BC59A6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apasat_1-1695042861200.png" alt="apasat_1-1695042861200.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I made a rule for this website in screenshot based on it's URL, but it's still working. After this, I banned it's IP addresses, and it stopped working (rule worked fine).&lt;/P&gt;&lt;P&gt;Can someone explain me why FTD does not block websites, but sends logs that it's blocking?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 13:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925007#M1104309</guid>
      <dc:creator>apasat</dc:creator>
      <dc:date>2023-09-18T13:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925056#M1104314</link>
      <description>&lt;P&gt;If you looking to Block ( select Block) rather Block with reset&lt;/P&gt;
&lt;P&gt;more informaion explained here block and block with reset (other options)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://rayka-co.com/lesson/ftd-access-control-policy/" target="_blank"&gt;https://rayka-co.com/lesson/ftd-access-control-policy/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 14:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925056#M1104314</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-09-18T14:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925680#M1104365</link>
      <description>&lt;P&gt;I've tried both ways, but the sites are still available, although in connections events I see that it have been blocked based on rule (for example Gambling)&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 11:05:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925680#M1104365</guid>
      <dc:creator>apasat</dc:creator>
      <dc:date>2023-09-19T11:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925690#M1104367</link>
      <description>&lt;P&gt;Could it be the sites you tested were cached on the endpoint you tested from? if you try to ping one of those URL's would you get any responses?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 11:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925690#M1104367</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-09-19T11:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925702#M1104369</link>
      <description>&lt;P&gt;I've accessed these pages from many workstations, also cleared cache. And yes, I get icmp responses, also telnet on 80/443 is ok. So, FTD does not block traffic&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 11:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925702#M1104369</guid>
      <dc:creator>apasat</dc:creator>
      <dc:date>2023-09-19T11:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925721#M1104372</link>
      <description>&lt;P&gt;Add dns server IP to ftd' make sure ftd can resolve the ip.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 12:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925721#M1104372</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-09-19T12:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925748#M1104377</link>
      <description>&lt;P&gt;There's already DNS servers. The problem is that some of sites are blocked, and some are not,&amp;nbsp;&lt;SPAN&gt;although in connections events I can see that FTD kind restricted access (it didn't).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 12:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925748#M1104377</guid>
      <dc:creator>apasat</dc:creator>
      <dc:date>2023-09-19T12:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925762#M1104378</link>
      <description>&lt;P&gt;Some sites block some not'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check site allow is bypass by prefilter acl or it already have conn.&lt;/P&gt;
&lt;P&gt;If it have conn try clear conn and check again.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 13:09:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925762#M1104378</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-09-19T13:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925793#M1104380</link>
      <description>&lt;P&gt;I've just accessed 1xbet.com (gambling site), it works fine, but conn events says that it's blocked (and one line that it's uncategorized and allowed).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apasat_0-1695131717846.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197693i8028D81DC559B86F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="apasat_0-1695131717846.png" alt="apasat_0-1695131717846.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 13:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4925793#M1104380</guid>
      <dc:creator>apasat</dc:creator>
      <dc:date>2023-09-19T13:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD does not block sites based on URL rule</title>
      <link>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4926529#M1104419</link>
      <description>&lt;P&gt;Dumb question..&amp;nbsp; Did you deploy?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 12:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-does-not-block-sites-based-on-url-rule/m-p/4926529#M1104419</guid>
      <dc:creator>obrien2010</dc:creator>
      <dc:date>2023-09-20T12:11:25Z</dc:date>
    </item>
  </channel>
</rss>

