<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using ftd to block subdomains on the internet. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268835#M1119929</link>
    <description>&lt;P&gt;how can I tell fmc/ftd DNS resolution is working? It is configured on FMC. but DNS is NOT resolving for FQDN's or URL's. I can ssh into the cli on the ftd and ping internal and external by name.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Mar 2025 22:05:35 GMT</pubDate>
    <dc:creator>tryingtofixit</dc:creator>
    <dc:date>2025-03-07T22:05:35Z</dc:date>
    <item>
      <title>Using ftd to block subdomains on the internet.</title>
      <link>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268795#M1119924</link>
      <description>&lt;P&gt;I need to lock javada1.oracle.com, javadl-esd-secure.oracle.com, java.com and java.net.&lt;/P&gt;&lt;P&gt;Can I do this using a FQDN object and a deny access rule?&amp;nbsp; What is the process for blocking subdomains with the ftd?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 17:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268795#M1119924</guid>
      <dc:creator>tryingtofixit</dc:creator>
      <dc:date>2025-03-07T17:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Using ftd to block subdomains on the internet.</title>
      <link>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268804#M1119925</link>
      <description>&lt;P&gt;Yes, you can use FQDN objects to do this. You will need an object for each FQDN that you want to block:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/objects-object-mgmt.html?bookSearch=true" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/objects-object-mgmt.html?bookSearch=true&lt;/A&gt;&lt;/P&gt;
&lt;PRE&gt;You can use FQDN objects in access control rules and prefilter rules, or manual NAT rules, only. &lt;BR /&gt;The rules match the IP address obtained for the FQDN through a DNS lookup. &lt;BR /&gt;To use an FQDN network object, ensure you have configured the DNS server settings in DNS Server Group&lt;BR /&gt;and the DNS platform settings in DNS.&lt;/PRE&gt;
&lt;DIV id="bodyDisplay_3" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 07 Mar 2025 18:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268804#M1119925</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2025-03-07T18:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Using ftd to block subdomains on the internet.</title>
      <link>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268819#M1119928</link>
      <description>&lt;P&gt;thanks for the link. I have it configured as a fqdn object in block access rule. dns is enabled and working on the fmc to the ftd.&amp;nbsp; nothing gets blocked. got any troubleshooting links ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 20:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268819#M1119928</guid>
      <dc:creator>tryingtofixit</dc:creator>
      <dc:date>2025-03-07T20:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using ftd to block subdomains on the internet.</title>
      <link>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268835#M1119929</link>
      <description>&lt;P&gt;how can I tell fmc/ftd DNS resolution is working? It is configured on FMC. but DNS is NOT resolving for FQDN's or URL's. I can ssh into the cli on the ftd and ping internal and external by name.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 22:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268835#M1119929</guid>
      <dc:creator>tryingtofixit</dc:creator>
      <dc:date>2025-03-07T22:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Using ftd to block subdomains on the internet.</title>
      <link>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268858#M1119930</link>
      <description>&lt;P&gt;Can you confirm the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You have DNS objects configured: Object -&amp;gt; Object Management -&amp;gt; DNS Server Group&lt;/LI&gt;
&lt;LI&gt;DNS is configured on FTD: Devices -&amp;gt; Platform Settings -&amp;gt; DNS:
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Enable DNS name resolution by device&lt;/LI&gt;
&lt;LI&gt;DNS Server Groups contains the DNS object from above&lt;/LI&gt;
&lt;LI&gt;The correct interface objects are selected for DNS resolution&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;Post the output from the following commands in the FTD cli: system support diagnostic-cli -&amp;gt; enable:
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;show run dns&lt;/LI&gt;
&lt;LI&gt;ping &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Extended ping: ping -&amp;gt; TCP Ping [n] -&amp;gt; Interface [Desired interface] -&amp;gt; Target IP address [&lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;] &amp;gt; Repeat count [5] -&amp;gt; Datagram size [100] -&amp;gt; Timeout in seconds [2] -&amp;gt; Extended commands [n] -&amp;gt; Sweep range of size [n]&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 23:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-ftd-to-block-subdomains-on-the-internet/m-p/5268858#M1119930</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2025-03-07T23:10:36Z</dc:date>
    </item>
  </channel>
</rss>

