Should blocking URL ign.com also blocks verisign.com? Seeing conflict with Cisco documentation...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-05-2020 08:46 PM
I just tested blocking ign.com, but I can confirm it does not block versign.com. Thoughts? I seem to be in conflict with the documentation below. I'm testing with FMC and FTD 6.6. Screenshots attached below. When I go to versign.com it see it's matching the allow rule.
To determine whether network traffic matches a URL condition, the system performs a simple substring match. Matching is NOT anchored at the top level domain. If the allowed string matches any part of the requested URL, the URLs are considered to match.
Example 1:
You want to explicitly block ign.com (a gaming site). However, substring matching means that blocking ign.com also blocks verisign.com.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-05-2020 11:26 PM
You get it right, blocking ign.com will block all the root domain which is (
ign.com) and all sub domains (*.ign.com). But it will not block root
domains that include the keyword (ign.com).
It is not *ign.com but it is *.ign.com. Hope this is helpful.
**** please remember to rate useful posts
