03-07-2025 09:50 AM
I need to lock javada1.oracle.com, javadl-esd-secure.oracle.com, java.com and java.net.
Can I do this using a FQDN object and a deny access rule? What is the process for blocking subdomains with the ftd?
03-07-2025 10:51 AM - edited 03-07-2025 10:51 AM
Yes, you can use FQDN objects to do this. You will need an object for each FQDN that you want to block: https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/objects-object-mgmt.html?bookSearch=true
You can use FQDN objects in access control rules and prefilter rules, or manual NAT rules, only.
The rules match the IP address obtained for the FQDN through a DNS lookup.
To use an FQDN network object, ensure you have configured the DNS server settings in DNS Server Group
and the DNS platform settings in DNS.
Thank you for rating helpful posts!
03-07-2025 12:12 PM
thanks for the link. I have it configured as a fqdn object in block access rule. dns is enabled and working on the fmc to the ftd. nothing gets blocked. got any troubleshooting links ?
03-07-2025 01:38 PM - edited 03-07-2025 02:05 PM
how can I tell fmc/ftd DNS resolution is working? It is configured on FMC. but DNS is NOT resolving for FQDN's or URL's. I can ssh into the cli on the ftd and ping internal and external by name.
03-07-2025 03:10 PM
Can you confirm the following:
Thank you for rating helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide