cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4087
Views
2
Helpful
6
Replies

Firepower - Geoblocking countries

Humongous
Level 1
Level 1

I geoblock traffic from most countries.  I have run into a few websites that my clients need access to but are located in one of the blocked countries.  Is there a way to allow these websites through AND continue to block other traffic from the country w/o having to purchase the URL Filtering license from Cisco?  Thanks in advance!

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

If you want to take any policy action (monitor, block, allow by exception, etc.) for individual URL categories/reputations then you need the URL Filtering licensing.

(2024-09-21: edited for accuracy - hand coded individual URLs do not require the additional license.)

View solution in original post

6 Replies 6

Marvin Rhoads
Hall of Fame
Hall of Fame

If you want to take any policy action (monitor, block, allow by exception, etc.) for individual URL categories/reputations then you need the URL Filtering licensing.

(2024-09-21: edited for accuracy - hand coded individual URLs do not require the additional license.)

That is what I thought - just wanted to verify - thanks!

Were you trying to allow a specific URL (http://example.com/thing1.html) or just the site (example.com or 150.234.210.205)?

The latter shouldn't take a URL filtering license; the Security Intelligence whitelist/blocklist can handle that.

(I realize this was a year and a half ago...)

Ty Rost
Cisco Employee
Cisco Employee

This post is a bit older, but the solution is not correct. Manual URL filtering by use of URL groups and objects does not require a URL license. "Without a URL Filtering license, you can specify individual URLs or groups of URLs to allow or block. This option gives you granular, custom control over web traffic, but does not allow you to use URL category and reputation data to filter network traffic."

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/740/management-center-admin-74/system-licenses.html#reference_0FB126619D0649D79B4F666AACE82BAD

You are correct @Ty Rost - I should have added "categories".

I edited my post to reflect that correction

Categories and reputation.   

Review Cisco Networking for a $25 gift card