<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firepower custom URL feed in ACP rule in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5197026#M1115981</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not interfering with the lists provided by Talos.&amp;nbsp; I am adding additional custom URL feeds for domains that do not appear in Talos.&amp;nbsp; These URL feeds will be used in ACP rules, not SI.&amp;nbsp; &amp;nbsp;For example, let's say I have an ACP rule that blocks the category "Shopping" but I need to make an exception for amazon.com (the users will kill me if I don't allow Amazon, right?).&amp;nbsp; Adding it to SI global-do-not-block will not bypass the ACP block of "shopping" sites.&amp;nbsp; However, I can add an ACP rule before the shopping rule that references my custom URL feed.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously, I can just add URLs manually to this rule but that would require access to FMC and a deployment to the FTD.&amp;nbsp; By storing this feed on a protected server share we can allow authorized non-tech, non-FMC users to add exceptions for domains and also have the change take effect withing minutes without needing a deploy.&lt;/P&gt;&lt;P&gt;We can do similar with domains that we want blocked but in that case I would use the custom feed directly in SI because a block in SI is final and will not go to the ACP.&lt;/P&gt;&lt;P&gt;HTH&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Sep 2024 18:40:55 GMT</pubDate>
    <dc:creator>tato386</dc:creator>
    <dc:date>2024-09-20T18:40:55Z</dc:date>
    <item>
      <title>firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5195843#M1115888</link>
      <description>&lt;P&gt;My understanding is that URL feeds in FirePower SI are updated dynamically and take effect w/o having to do a policy deploy to the FTD. Does the same apply to custom URL feeds used in an ACP rule? My idea would be to create a custom URL feed on a local web server which is then used in an ACP rule. Local admins would have access to the URL feed file on the webserver and can edit this file(s) to block or allow URLs w/o having access to the FMC or FTD. Will this work?&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 12:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5195843#M1115888</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-09-18T12:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5195866#M1115890</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317180"&gt;@tato386&lt;/a&gt; yes, create the custom URL feed and define an update frequency for the FMC to automatically check for updates, policy should not need to deployed.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 13:06:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5195866#M1115890</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-09-18T13:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5195941#M1115900</link>
      <description>&lt;P&gt;cool.&amp;nbsp; is there a file or folder on the FTD that I can use to check the status of this feed?&amp;nbsp; I know I can just test by generating some traffic that matches the ACP rule but seems easier just to SSH into the FTD and poke around.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 15:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5195941#M1115900</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-09-18T15:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5195945#M1115901</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317180"&gt;@tato386&lt;/a&gt; try the relevant FTD folder below:-&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_2-1726674735024.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/229367iFD8DEF0C94D74AF3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RobIngram_2-1726674735024.png" alt="RobIngram_2-1726674735024.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 15:53:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5195945#M1115901</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-09-18T15:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5196027#M1115911</link>
      <description>&lt;P&gt;FTD gets the update pretty quick from the FMC, nice.&lt;/P&gt;&lt;P&gt;you da man!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 19:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5196027#M1115911</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-09-18T19:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5196842#M1115964</link>
      <description>&lt;P&gt;Why you correct the URL receive from talos ? and even if you remove some URL you need to do this process each time the talos send update&lt;/P&gt;
&lt;P&gt;so there are two list&amp;nbsp;&lt;BR /&gt;Block-list and Do-not-block-list&amp;nbsp;&lt;BR /&gt;add URL you need to allow under block list&amp;nbsp;&lt;BR /&gt;and this way you dont need each time add/remove url from talos list&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="security-intellegince-is-part-of-access-control-1536x623.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/229546i89780456F5916AE8/image-size/large?v=v2&amp;amp;px=999" role="button" title="security-intellegince-is-part-of-access-control-1536x623.png" alt="security-intellegince-is-part-of-access-control-1536x623.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 11:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5196842#M1115964</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-20T11:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5197026#M1115981</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not interfering with the lists provided by Talos.&amp;nbsp; I am adding additional custom URL feeds for domains that do not appear in Talos.&amp;nbsp; These URL feeds will be used in ACP rules, not SI.&amp;nbsp; &amp;nbsp;For example, let's say I have an ACP rule that blocks the category "Shopping" but I need to make an exception for amazon.com (the users will kill me if I don't allow Amazon, right?).&amp;nbsp; Adding it to SI global-do-not-block will not bypass the ACP block of "shopping" sites.&amp;nbsp; However, I can add an ACP rule before the shopping rule that references my custom URL feed.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously, I can just add URLs manually to this rule but that would require access to FMC and a deployment to the FTD.&amp;nbsp; By storing this feed on a protected server share we can allow authorized non-tech, non-FMC users to add exceptions for domains and also have the change take effect withing minutes without needing a deploy.&lt;/P&gt;&lt;P&gt;We can do similar with domains that we want blocked but in that case I would use the custom feed directly in SI because a block in SI is final and will not go to the ACP.&lt;/P&gt;&lt;P&gt;HTH&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 18:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5197026#M1115981</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-09-20T18:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5197496#M1115997</link>
      <description>&lt;P&gt;Friends there is fqdn and dns and url&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I think you talking about using fqdn not url, url always done in SI.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can I see the ACP you use&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks alot&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 10:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5197496#M1115997</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-23T10:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5197763#M1116013</link>
      <description>&lt;P&gt;If you create custom feeds they will be available for use in ACP rules.&amp;nbsp; In my case the feed files are simple text files that look like this:&lt;/P&gt;&lt;P&gt;domain1.com&lt;/P&gt;&lt;P&gt;domain2.com&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tato386_0-1727115208032.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/229717i14EA19CDBFDF0C30/image-size/large?v=v2&amp;amp;px=999" role="button" title="tato386_0-1727115208032.png" alt="tato386_0-1727115208032.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 18:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5197763#M1116013</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-09-23T18:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: firepower custom URL feed in ACP rule</title>
      <link>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5221854#M1117431</link>
      <description>&lt;P&gt;Sorry I take me some time to reply but really I am busy&amp;nbsp;&lt;BR /&gt;anyway&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you me confuse and after some deep dive I brief what I get&amp;nbsp;&lt;BR /&gt;URL&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- using URL filtering which is use&amp;nbsp;&lt;BR /&gt;A- manual URL (object)&amp;lt;&amp;lt;- this what you looking for&amp;nbsp;&lt;BR /&gt;B- category URL (need license dynamic feed)&lt;BR /&gt;&lt;BR /&gt;2-URL SI&amp;nbsp;&lt;BR /&gt;A- Talos&lt;BR /&gt;B- custom list feed &amp;lt;&amp;lt;- this what I was mention above&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://rayka-co.com/lesson/cisco-ftd-url-filtering/#:~:text=Cisco%20FTD%20URL%20Filtering%20Concept&amp;amp;text=Reputations%20are%20from%20trusted%20websites,that%20come%20in%20each%20category.&amp;amp;text=If%20you%20allow%20a%20reputation,levels%20will%20be%20also%20blocked" target="_blank"&gt;https://rayka-co.com/lesson/cisco-ftd-url-filtering/#:~:text=Cisco%20FTD%20URL%20Filtering%20Concept&amp;amp;text=Reputations%20are%20from%20trusted%20websites,that%20come%20in%20each%20category.&amp;amp;text=If%20you%20allow%20a%20reputation,levels%20will%20be%20also%20blocked&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;MHM&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 08:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-custom-url-feed-in-acp-rule/m-p/5221854#M1117431</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-11-08T08:04:01Z</dc:date>
    </item>
  </channel>
</rss>

