04-20-2018 07:49 AM - edited 02-21-2020 07:39 AM
Hello,
from what I've read to do HTTPS url object filtering Cisco FirePower will check the Certificate CN name, will it also check the SAN entries?
Just wondering how it will work with a singel CN name and multiple SAN names on a cert used across multiple web sites.
Solved! Go to Solution.
04-20-2018 11:59 AM
no it does not check the subdomains listed in the certificate, so do not use subdomains when creating the HTTPS filter. Instead use company.com (and not www.company.com). In this case the filter will match the entire host name including subdomains.
04-20-2018 11:59 AM
no it does not check the subdomains listed in the certificate, so do not use subdomains when creating the HTTPS filter. Instead use company.com (and not www.company.com). In this case the filter will match the entire host name including subdomains.
04-25-2018 01:41 AM
Thanks for clarification
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide