cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
525
Views
0
Helpful
8
Replies

Blocking AI using Ironport

Griffin-s
Level 1
Level 1

Hello All, 

Any suggestions on how we can block some AI sites but allow a select few others? 

8 Replies 8

So, assuming there’s a category for AI, you block that in your global access policy. 

Then create a category called “AllowedAI” and put the sites you’ll allow in that category.

Then in the access policy, put together the allowed users/ips/agent strings (in the circle) and put your custom category in the box under "URL filtering"

accesspolicy.png

Ken, 

Thanks for that. When you say "a category for AI" in our global access policy where would that be located? Is that something our organization would have to build? I am not finding that. 

So... TalosIntelligence has a Generative AI category, but it doesn't look to have made it to the WSA yet. 

@amojarra any news on that front? 

Hi @Ken Stieers 

Sorry for the late reply 

we have the Generative AI in the WSA: 

amojarra_0-1758622722523.png

there are some customers who might not seeing this, due to some updates Issue, they need to contact TAC to check from the backend. 

on the other hand regarding the question:

Any suggestions on how we can block some AI sites but allow a select few others? 

So WSA, first checks the Custom URL Categories then the Pre-Defined categories, you can block all AI category and define your permitted AI sites in the custom URL category, make sure to add that category in your policy that you are blocking the "generative AI" and set that custom category to Allow or Pass through depends on your policy. 

 

And in case you are looking for some extra layer of security on your AI access, you can review Cisco's AI Defense: 

https://www.cisco.com/site/us/en/products/security/ai-defense/index.html

 

 

Regards,

Amirhossein Mojarrad

+++++++++++++++++++++++++++++++++++++++++++++++++++

++++     If you find this answer helpful, please rate it as such    ++++

+++++++++++++++++++++++++++++++++++++++++++++++++++

 

 

Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++

Sorry... I was asking if the WSA was getting the Gemerative AI category.

I don't have a WSA anymore so couldn't check, but the docs that are available don't show it...


@Ken Stieers 

Thank you so much for bringing this to my attention. 

I have filed an internal Documentation Correction request  "[Doc] Adding "Generative AI" to the Pre-Defined URL Category table

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwr40214

 

BR

Amir 

 

Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++

Ok... so it is in the product, but not documentation...
I figured that once WSA was synced with the Talos list, it would stay in sync... but had no way to verify it any longer.
All the best!

Ken

balaji.bandi
Hall of Fame
Hall of Fame
Any suggestions on how we can block some AI sites but allow a select few others? 

any web site normal in terms of WSA , so we do as this you can only by access policy unlike any other web sites (we block and allow)

I have come across this but i have not gone more detailed have a look :

https://community.cisco.com/t5/secure-access-announcements/generative-ai-content-category/ta-p/5257734

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help