cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
636
Views
0
Helpful
2
Replies

FirePower HTTPS URL Filerting

istewart11
Level 1
Level 1

Hello,

 

from what I've read to do HTTPS url object filtering Cisco FirePower will check the Certificate CN name, will it also check the SAN entries?

 

Just wondering how it will work with a singel CN name and multiple SAN names on a cert used across multiple web sites.

1 Accepted Solution

Accepted Solutions

no it does not check the subdomains listed in the certificate, so do not use subdomains when creating the HTTPS filter.  Instead use company.com (and not www.company.com).  In this case the filter will match the entire host name including subdomains.

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

2 Replies 2

no it does not check the subdomains listed in the certificate, so do not use subdomains when creating the HTTPS filter.  Instead use company.com (and not www.company.com).  In this case the filter will match the entire host name including subdomains.

--
Please remember to select a correct answer and rate helpful posts

Thanks for clarification 

Review Cisco Networking for a $25 gift card