cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2402
Views
10
Helpful
1
Replies

Difference between security intelligence and url filtering on cisco ftd

Gab
Level 1
Level 1

what is the difference betwenn URL filtering Feature and URL, DNS, IP Address feature from Security Intelligence? Where should i apply the url filtering feature and when the security intelligence feature? I am confuse about these two feauture because they are almost the same. Please if you can help me with this question.

1 Reply 1

Rahul Govindan
VIP Alumni
VIP Alumni

URL filtering gives you the ability to create policies based on Reputation score or category. This is controlled by the URL database hosted by BrightCloud.

 

Security Intelligence has information published by Talos about good/bad ip addresses, networks and urls. This is different from url filtering as there is reputation or category based differentiation for url's. The only categories that come default with Talos are the different types of bad networks/urls (eg, Malware, Phishing, CnC etc.)

 

So if you want to create a policy to block all social media sites or to block all sites below a certain reuptation - use URL filtering. This requires a separate license. 

If you want to block traffic to all known bad ip address/urls - Use Security intelligence. I recommend using SI in every deployment, irrespective of the other features you have enabled. 

Review Cisco Networking for a $25 gift card