Difference between security intelligence and url filtering on cisco ftd
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2018 01:54 PM - edited 02-21-2020 08:03 AM
what is the difference betwenn URL filtering Feature and URL, DNS, IP Address feature from Security Intelligence? Where should i apply the url filtering feature and when the security intelligence feature? I am confuse about these two feauture because they are almost the same. Please if you can help me with this question.
- Labels:
-
Firepower Threat Defense (FTD)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2018 05:33 PM
URL filtering gives you the ability to create policies based on Reputation score or category. This is controlled by the URL database hosted by BrightCloud.
Security Intelligence has information published by Talos about good/bad ip addresses, networks and urls. This is different from url filtering as there is reputation or category based differentiation for url's. The only categories that come default with Talos are the different types of bad networks/urls (eg, Malware, Phishing, CnC etc.)
So if you want to create a policy to block all social media sites or to block all sites below a certain reuptation - use URL filtering. This requires a separate license.
If you want to block traffic to all known bad ip address/urls - Use Security intelligence. I recommend using SI in every deployment, irrespective of the other features you have enabled.
