cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1053
Views
0
Helpful
4
Replies

Open Web Traffic on an FMC

Vic48
Level 1
Level 1

I'm trying to open web traffic to: upgrade.bitdefender.com on an FMC. I made a change to the access control rules as indicated in the attached pic, but it's had no effect. Is the correct policy to modify?

 

Thanks!

4 Replies 4

nspasov
Cisco Employee
Cisco Employee

Is this for actual web traffic? Like users trying to browse to that URL? I ask this because the URL object that you have defined is for web browsing sessions. If you want to open your policy for other (Non web-based sessions) to upgrade.bitdefender.com without using an IP/subnet, you will need to utilize the FQDN-based objects that were introduced in version 6.4.0.

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/reusable_objects.html

I hope this helps!

Thank you for rating helpful posts!

So just to make sure we're on the same page...if we're trying to open the traffic via the application rather than a browser then we would use FQDN-based objects to implement it. Is that right?

I just found out that this FMC is running v.6.2.3.2. How would it be handled in this version? Would it be under URL?

nspasov
Cisco Employee
Cisco Employee

You will have to upgrade your FMC and managed sensors/firewalls to 6.4.0.x in order to get support for FQDN objects. In fact, 6.4.0.4 is the current recommended/Gold starred release. 

Thank you for rating helpful posts!

Review Cisco Networking for a $25 gift card