cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
34751
Views
36
Helpful
12
Replies

Using wildcard in URL filtering

lyutov_dv
Level 1
Level 1

hi,

 

How can i block all connections to *.microsoft.com (for example)?

Can i use custom URL object *.microsoft.com or firepower doesnt support wildcards?

2 Accepted Solutions

Accepted Solutions

I remember not long ago opened a cisco tac with similar issue. and TAC advise to use a WSA. according to them FMC/Firepower sensor do not support wild card in URL filtering.
please do not forget to rate.

View solution in original post

Sorry about that  - you are correct. I found a technote mentioning this as well:

 

https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118852-technote-firesight-00.html#anc14

 

I tested on my FMC just now and found the same. However if I instead use microsoft.com instead of *.microsoft.com as my url object it works due to substring matching as described in the technote.

View solution in original post

12 Replies 12

Marvin Rhoads
Hall of Fame
Hall of Fame

Firepower support wilcards in URL objects.

 

See the screenshot below taken from my FMC 6.2.2:

 

FMC URL object with wildcard.PNG

I can create an object but it doesn't work in access rules

Sorry about that  - you are correct. I found a technote mentioning this as well:

 

https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118852-technote-firesight-00.html#anc14

 

I tested on my FMC just now and found the same. However if I instead use microsoft.com instead of *.microsoft.com as my url object it works due to substring matching as described in the technote.

Yes I found this technote...

it works but it's not the same because for example oldmicrosoft.com will be blocked as well, but it's another domain

Quite true - that is a limitation of the current platform.

 

I will remember to bring this up with the Cisco engineers at next week's Security team event.

So, what was the resolution to this?

 

We have a URL blacklist, with, as an example, 777.com in it.

 

777.com blocks, but www.777.com does not.

So, it appears the substring matching works if I create an actual URL object, then block it.

 

Substring matching, however, does not work, when populating a blacklist/whitelist in the Security Intelligence URL Lists and Feeds.

This document might be helpful FTD URL Filtering - How it works?

I remember not long ago opened a cisco tac with similar issue. and TAC advise to use a WSA. according to them FMC/Firepower sensor do not support wild card in URL filtering.
please do not forget to rate.

evan.chadwick1
Level 1
Level 1

what came of this.
IF Firepower can not process wildcard, why does the product allow them to be created. Surely its not that hard to detect a wildcard and not save it and put up a screen that advises so?

Rokib Hasan
Level 1
Level 1

Firepower does support wildcard, but not this format like  (*.microsoft.com) rather it support (.microsoft.com) format. You can create a URL object with value (.microsoft.com) for blocking all microsoft.com domain, it will block for support.microsoft.com/ www.update.microsoft.com/  or any other sub domain after .microsoft.com. So use dot(.) instead of asterisk(*) it will work fine. I am testing it in production environment.

bcoverstone
Level 1
Level 1

In FDM, all sub-websites match by just using the base domain name.

Therefore, just enter microsoft.com

Do not include an asterisk (i.e. *.microsoft.com)

Do not include a dot (i.e. .microsoft.com)

 

This will match microsoft.com, abc.microsoft.com, and abc.update.microsoft.com 

However, notmicrosoft.com will not match

 

I have been testing this successfully. Here's the reference:

Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager, Version 6.2.3 - Objects [Cisco Firepower NGFW] - Cisco

Look under Configuring URL Objects and Groups

 

I'm using version 7.0.0.1 with FDM, I don't know if previous 6.x versions worked the same way.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card