cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5342
Views
0
Helpful
7
Replies

Blocking sub domain in URL filtering

InTheJuniverse
Level 1
Level 1

Hello

 

We are on Cisco FMC 2500, Code version 6.2.3

 

Is it possible to

 

1)  Block url1.example.com and allow www.example.com?

 

2) Allow url2.example.com, block url1.example.com,  and allow www.example.com?

 

3) Allow child domains and  block parent domain?

 

I have read documentation that this is not possible, but trying forums just in case :) 

 

Thank you very much.

2 Accepted Solutions

Accepted Solutions

Abheesh Kumar
VIP Alumni
VIP Alumni

Hi,

Try creating like below screenshot, allow the subdomians first and then block the parent domain.

2018-12-26 13_32_21-Cisco Firepower Management Center for VMWare 6.3.0 Build 83 (GUEST-FMC) - admin.jpg

 

FMC will not support to block wildcard

 

Create allow rule with url1.example.com then create block rule for example.com

This way you can achive this but you need to specify all you child domains.

 

Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question

 

View solution in original post

Abhishek, thank you.

 

Our policies are designed such that the Global Whitelist / Blacklist Objects are inherited to every Domain and applied first thru section 'Mandatory Global Policies', followed by "Default DomainName policy".

 

So, a policy into Child domain will look something like this (please check screen shot)

 

Just before reading your response, I created a similar policy and awaiting user confirmation.

 

I am assuming this will work because the "subdomain" sites I want to block are not allowed explicitly in Global Policy, 

 

Waiting for user confirmation.

 

Thank you in advance.

 

View solution in original post

7 Replies 7

Sheraz.Salim
VIP Alumni
VIP Alumni

this is not possible. we had similar issue open TAC and TAC advise to use cisco web security appliance. (WSA).

 

please do not forget to rate.

Abheesh Kumar
VIP Alumni
VIP Alumni

Hi,

Try creating like below screenshot, allow the subdomians first and then block the parent domain.

2018-12-26 13_32_21-Cisco Firepower Management Center for VMWare 6.3.0 Build 83 (GUEST-FMC) - admin.jpg

 

FMC will not support to block wildcard

 

Create allow rule with url1.example.com then create block rule for example.com

This way you can achive this but you need to specify all you child domains.

 

Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question

 

Abhishek, thank you.

 

Our policies are designed such that the Global Whitelist / Blacklist Objects are inherited to every Domain and applied first thru section 'Mandatory Global Policies', followed by "Default DomainName policy".

 

So, a policy into Child domain will look something like this (please check screen shot)

 

Just before reading your response, I created a similar policy and awaiting user confirmation.

 

I am assuming this will work because the "subdomain" sites I want to block are not allowed explicitly in Global Policy, 

 

Waiting for user confirmation.

 

Thank you in advance.

 

If this doesn't work, create a URL object and try creating specific rules. Anyway plz reply with the user confirmation

Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question

It works this way, thanks.

 

I got another problem with http and https blocking, but I am going to try something and get back.

 

Thank you.

Try with url without specifying http/https, any way let us know with your output.

HTH
Abheesh

Ok problem resolved. Using Objects or URLs in the ACP made no difference.

Review Cisco Networking for a $25 gift card