<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD URL filtering is not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320190#M1122239</link>
    <description>&lt;P&gt;Does the firewall have a DNS configuration so that it knows how to resolve and categorize URLs by their DNS entry?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Aug 2025 04:49:04 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2025-08-13T04:49:04Z</dc:date>
    <item>
      <title>FTD URL filtering is not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320187#M1122238</link>
      <description>&lt;P&gt;I manage an ISA 3000 firewall running FTD 7.4.2.3-4 using the FDM. This is for a small site with just this one firewall. There is no FMC and we do not want FMC. The device will be managed through FDM. We have all the NGFW licenses for the FTD (IPS/IDS, Malware, URL). When configuring access policies to block website categories, the URL filtering is not working at all. After trying to open any of the risky websites, say cryptocurrency or pornography websites, the websites still open just fine. When checking the hit counter of the rules, I see that the block rule never gets hit, even though it is listed&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;before&lt;/STRONG&gt;&lt;/U&gt; the general allow rule. See attached screenshot of my configuration. What am I doing wrong here?&lt;/P&gt;&lt;P&gt;PS: Do not worry about rule #2. We are testing a few things and this blanket allow rule only applies to traffic from inside vlans to other inside vlans, not towards the internet.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 04:25:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320187#M1122238</guid>
      <dc:creator>Scryden2</dc:creator>
      <dc:date>2025-08-13T04:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTD URL filtering is not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320190#M1122239</link>
      <description>&lt;P&gt;Does the firewall have a DNS configuration so that it knows how to resolve and categorize URLs by their DNS entry?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 04:49:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320190#M1122239</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-08-13T04:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD URL filtering is not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320193#M1122241</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Yes. Please see attached screenshots. It is also able to communicate with SMARTnet and retrieve VDB and intrusion updates just fine.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 04:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320193#M1122241</guid>
      <dc:creator>Scryden2</dc:creator>
      <dc:date>2025-08-13T04:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD URL filtering is not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320194#M1122242</link>
      <description>&lt;P&gt;Ok, that all appears correct.&lt;/P&gt;
&lt;P&gt;If you enter a test URL in the filtering section, does it get categorized as expected?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 05:04:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320194#M1122242</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-08-13T05:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTD URL filtering is not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320196#M1122243</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Please disregard. I found my own mistake. I recently changed the gateway for the management interface and I punched in the wrong IP address. After updating it to the correct one the URL filtering now seems to be working.&lt;/P&gt;&lt;P&gt;One thing I do want to clarify though is the following:&lt;BR /&gt;When a URL is part of 2 separate URL categories, and I have only 1 blocked but not the other, the website is permitted. For example, I am blocking the category 'cryptocurrency' but not 'online trading'. One of the crypto websites I am testing with is in both the category 'cryptocurrency' and 'online trading', according to Cisco Talos. I can open the website just fine. This company needs to have access to trading platforms but wants to exclude crypto platforms. Is this expected behavior of the firewall and is the only way around it to manually block the URLs in question?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 05:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320196#M1122243</guid>
      <dc:creator>Scryden2</dc:creator>
      <dc:date>2025-08-13T05:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTD URL filtering is not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320230#M1122245</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/difference-between-security-intelligence-and-url-filtering-on/td-p/3682603" target="_blank"&gt;https://community.cisco.com/t5/network-security/difference-between-security-intelligence-and-url-filtering-on/td-p/3682603&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are two&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Url filter and SI url' you can use both to achieve what you want&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 08:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-filtering-is-not-working/m-p/5320230#M1122245</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-13T08:52:17Z</dc:date>
    </item>
  </channel>
</rss>

