10-25-2021 06:34 PM
10-26-2021 12:26 AM - edited 10-26-2021 12:27 AM
Microsoft publishes a listing of the IP addresses its service map to. You can use that listing to create an object which can then be used in an ACL.
See this example:
https://github.com/chrivand/Firepower_O365_Feed_Parser
Cisco has also developed the Cisco Secure Dynamic Attributes Connector (CSDAC) which allows you to automate the process using newer versions of Cisco Secure Firewall (7.0+).
10-25-2021 08:35 PM
Hi ,
You should explain more what is your use case. eg .do you need routers or firewalls and your traffic flow?
10-25-2021 11:25 PM
hi MrBeginner,
let say an enterprise dont allow their employees access internet by default, they access to specific web site only they requested.
let say employee A requested access O365, but how the network admin takes to get this job done in firewall level?
O365 contains different URL, so it wont work if using URL as a security object?
10-26-2021 12:26 AM - edited 10-26-2021 12:27 AM
Microsoft publishes a listing of the IP addresses its service map to. You can use that listing to create an object which can then be used in an ACL.
See this example:
https://github.com/chrivand/Firepower_O365_Feed_Parser
Cisco has also developed the Cisco Secure Dynamic Attributes Connector (CSDAC) which allows you to automate the process using newer versions of Cisco Secure Firewall (7.0+).
10-26-2021 02:35 AM
10-26-2021 05:44 AM
If it's just a web site and not a collection of services then you can simply use an FQDN in your ACL.
10-26-2021 05:50 PM
if that web site have tons of FQDN inside? so i can only input those tons of FQDN one by one on firewall ACL?
10-28-2021 06:33 PM
Correct. Doing whitelisting (vs. blacklisting) can be a very tedious process. That's one reason why very few organizations use that approach.
10-25-2021 09:23 PM
Yes, at least 3 products can do that: Cisco Secure Firewall (formerly known as Firepower Threat Defense), Umbrella SIG and Cisco Secure Web Appliance (formerly known as WSA).
Which one is right for you (if any of them are) depends on a lot of things, as @MrBeginner alluded to.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide