cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6310
Views
0
Helpful
4
Replies

Objects with FQDN

WebOps eDreams
Level 1
Level 1

Hi!

is it possible to create an object with fqdn instead of ips?

 

thanks

4 Replies 4

ankojha
Level 3
Level 3

Hi, 

Yes, you can add FQDN under Object management ->URL.

Hope it helps.

Thanks,

Ankita

But this means you need a URL License on your firepower system. Before (on ASA) there existed FQDN objects without any URL Lic. Is this correct?

 

r Johannes

Sunil Kumar
Cisco Employee
Cisco Employee

On which appliance, you are asking to configure the FQDN.

If this is ASA, yes you can do it. Please have a look on this article 

https://supportforums.cisco.com/document/66011/using-hostnames-dns-access-lists-configuration-steps-caveats-and-troubleshooting

Firepower/Sourcefire supports FQDN for URL filtering purpose. You can also configure FQDN in Security Intelligence's blacklisting as to block the IP address based upon domains but port based filtering with FQDN is not possible.

Hi Sunil!

Actually thats what i was trying to do fqdn with port based filtering or application detection.

Basically we have several server/resources in our internal networks which we access by using fqdn (using internal dns) and the idea is to create acls but with diferent ports than 80 /443.

We found no way to accomplish this; only by using static ips but this is not a 'nice' way to do it.

Review Cisco Networking for a $25 gift card