cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

578
Views
0
Helpful
4
Replies
Highlighted
Beginner

Need to do URL Filtering from Internet to Enterprise Traffic.

At My Edge Firewall ( Firepower 8350 ) there is a Firewall rule where I am allowing ANY Internet Traffic reaching to One of my Public IP on Http and Https port.

 

Right Now I want to allow traffic from Certain Domain to be allowed to come in to my Public IP not from WHOLE Internet World. For example I want to allow incoming traffic to my Public IP from below domains.

 

https://*.cnn.com
https://*.bbc.com
http://*.ctv.com
https://*.blob.core.windows.net

 

Note that in my Edge Firewall I have URL Filtering License, is it possible that I can allow these URL's in the ACL to filter the traffic only from above domains ? does it work that way ?

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted

If it's a well known public service, the vendor sometimes documents their public IPs and keeps that documentation up-to-date. For instance, Microsoft does this for Office 365.

For less common domains, you're right. If it's a vendor that you partner with you can possibly arrange a private feed of their addresses and get updated when they change.

View solution in original post

4 REPLIES 4
Highlighted
Hall of Fame Guru

URL filtering only works by analyzing destination URLs.

If you want to restrict source domains, you would need to know their associated IP addresses and restrict based on those. You would put them in a network object and use it as the source in your Access Control Policy rule.

Highlighted

Problem of using the IP address is IP's are always changing and easy to get blocked when new IP Addresses are updated for those domains. What you say  ?

 

Is there any other thoughts Marvin ?

Highlighted

If it's a well known public service, the vendor sometimes documents their public IPs and keeps that documentation up-to-date. For instance, Microsoft does this for Office 365.

For less common domains, you're right. If it's a vendor that you partner with you can possibly arrange a private feed of their addresses and get updated when they change.

View solution in original post

Highlighted

Thank You Marvin...

Content for Community-Ad