I just tested blocking ign.com, but I can confirm it does not block versign.com. Thoughts? I seem to be in conflict with the documentation below. I'm testing with FMC and FTD 6.6. Screenshots attached below. When I go to versign.com it see it's matching the allow rule.
https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/url_filtering.html#ID-2189-0000027e
To determine whether network traffic matches a URL condition, the system performs a simple substring match. Matching is NOT anchored at the top level domain. If the allowed string matches any part of the requested URL, the URLs are considered to match.
Example 1:
You want to explicitly block ign.com (a gaming site). However, substring matching means that blocking ign.com also blocks verisign.com.