03-31-2015 03:48 AM - edited 03-12-2019 05:39 AM
Hi!
is it possible to create an object with fqdn instead of ips?
thanks
01-18-2016 08:33 AM
Hi,
Yes, you can add FQDN under Object management ->URL.
Hope it helps.
Thanks,
Ankita
10-18-2017 02:18 AM
But this means you need a URL License on your firepower system. Before (on ASA) there existed FQDN objects without any URL Lic. Is this correct?
r Johannes
01-18-2016 09:31 PM
On which appliance, you are asking to configure the FQDN.
If this is ASA, yes you can do it. Please have a look on this article
https://supportforums.cisco.com/document/66011/using-hostnames-dns-access-lists-configuration-steps-caveats-and-troubleshooting
Firepower/Sourcefire supports FQDN for URL filtering purpose. You can also configure FQDN in Security Intelligence's blacklisting as to block the IP address based upon domains but port based filtering with FQDN is not possible.
01-19-2016 01:21 AM
Hi Sunil!
Actually thats what i was trying to do fqdn with port based filtering or application detection.
Basically we have several server/resources in our internal networks which we access by using fqdn (using internal dns) and the idea is to create acls but with diferent ports than 80 /443.
We found no way to accomplish this; only by using static ips but this is not a 'nice' way to do it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide