12-26-2018 01:30 AM - edited 03-12-2019 07:11 AM
Hello
We are on Cisco FMC 2500, Code version 6.2.3
Is it possible to
1) Block url1.example.com and allow www.example.com?
2) Allow url2.example.com, block url1.example.com, and allow www.example.com?
3) Allow child domains and block parent domain?
I have read documentation that this is not possible, but trying forums just in case :)
Thank you very much.
Solved! Go to Solution.
12-26-2018 02:47 AM
Hi,
Try creating like below screenshot, allow the subdomians first and then block the parent domain.
FMC will not support to block wildcard
Create allow rule with url1.example.com then create block rule for example.com
This way you can achive this but you need to specify all you child domains.
Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question
12-26-2018 02:58 AM
Abhishek, thank you.
Our policies are designed such that the Global Whitelist / Blacklist Objects are inherited to every Domain and applied first thru section 'Mandatory Global Policies', followed by "Default DomainName policy".
So, a policy into Child domain will look something like this (please check screen shot)
Just before reading your response, I created a similar policy and awaiting user confirmation.
I am assuming this will work because the "subdomain" sites I want to block are not allowed explicitly in Global Policy,
Waiting for user confirmation.
Thank you in advance.
12-26-2018 02:27 AM
this is not possible. we had similar issue open TAC and TAC advise to use cisco web security appliance. (WSA).
12-26-2018 02:47 AM
Hi,
Try creating like below screenshot, allow the subdomians first and then block the parent domain.
FMC will not support to block wildcard
Create allow rule with url1.example.com then create block rule for example.com
This way you can achive this but you need to specify all you child domains.
Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question
12-26-2018 02:58 AM
Abhishek, thank you.
Our policies are designed such that the Global Whitelist / Blacklist Objects are inherited to every Domain and applied first thru section 'Mandatory Global Policies', followed by "Default DomainName policy".
So, a policy into Child domain will look something like this (please check screen shot)
Just before reading your response, I created a similar policy and awaiting user confirmation.
I am assuming this will work because the "subdomain" sites I want to block are not allowed explicitly in Global Policy,
Waiting for user confirmation.
Thank you in advance.
12-26-2018 03:57 AM - edited 12-26-2018 03:58 AM
If this doesn't work, create a URL object and try creating specific rules. Anyway plz reply with the user confirmation
Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question
12-27-2018 01:11 AM - edited 12-27-2018 01:17 AM
It works this way, thanks.
I got another problem with http and https blocking, but I am going to try something and get back.
Thank you.
12-27-2018 01:27 AM
12-28-2018 01:46 AM
Ok problem resolved. Using Objects or URLs in the ACP made no difference.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide