09-04-2020 01:40 AM
Dear support team,
I have a requirement to allow only windows update from specific IP address to the internet. The firewall we use FTD1010.
we used below link as reference for the URLs and ports to be allowed for windows update.
Unfortunately FTD doesnt allow to use wildcard with the FQDN. Kindly advice if there is any method to achieve the requirement.
Solved! Go to Solution.
09-18-2020 06:33 AM
I was able to achieve this by adding URL object in the FTD.
microsoft.com
windows.com
s-microsoft.com
windowsupdate.com
Then created a URL group and added to above URL objects.
Then created a policy to inside to outside to allow selected URL group only.
09-05-2020 04:57 AM
Are you managing with FMC or with the on-box FDM?
For FMC there is an open source project that allows you to import the Microsoft )365 addresses as an object and then use that in an Access Control Policy rule.
https://github.com/chrivand/Firepower_O365_Feed_Parser
09-07-2020 03:39 AM
Dear Marvin,
We are not using FMC. Small business purpose with on-box FDM.
09-18-2020 06:33 AM
I was able to achieve this by adding URL object in the FTD.
microsoft.com
windows.com
s-microsoft.com
windowsupdate.com
Then created a URL group and added to above URL objects.
Then created a policy to inside to outside to allow selected URL group only.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide