Hi to all ,
i am in the phase of implementing Security Intelligence to an FTD, and i noticed that there are numerous URLs that can be blocked via Security Intelligence when it is activated.
For example i noticed that there are (currently speaking) 2044 URLs in relation to CnC that are "bad" URLs and i suppose that FTD will never let you visit these pages when you have activated these rules in the right pane of security intelligence where you can drag them in the block list.
My question is what extra does the DNS policy offer in this situation? It has only 214 entries about CnC in comparison with the SI Bad URLs which are 2044 URLs.
The example with the CNCs is just an example , the same is true for all the other URL categories relevant to SI as well as DNS Policy.
Please refer to the attachments for more information.
Thanks
Ditter.