cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3460
Views
0
Helpful
4
Replies

Cisco Firepower Manuel URL Wildcards

Trying to open www.google.com/recaptcha/*.* using wildcard at end of url and block www.goolge.com.  The allow is above block google.  I get it to block fine its the allow that is giving me trouble.

 

 

 

2 Accepted Solutions

Accepted Solutions

Hi Marvin,

 

If I am not wrong wildcards matching for custom URLs is not supported and FTD only supports sub-string matches only. But if there is a match for the URL it can filter both HTTP and HTTPS URLs without requiring SSL decryption.

 

I don't think if SSL decryption is requiring for URL filtering of HTTPS sites.

 

Vaibhav

View solution in original post

I was distinguishing between Uniform Resource Locator (U R L) vs. Uniform Resource Identifier (U R I).

 

URL plus the path = URI. If you do not do SSL decrypt, a Firepower or FTD sensor will not parse the path.

View solution in original post

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

Unless you decrypt the SSL, you cannot filter on a URI - only the top level URL based on the domain name.

Hi Marvin,

 

If I am not wrong wildcards matching for custom URLs is not supported and FTD only supports sub-string matches only. But if there is a match for the URL it can filter both HTTP and HTTPS URLs without requiring SSL decryption.

 

I don't think if SSL decryption is requiring for URL filtering of HTTPS sites.

 

Vaibhav

I was distinguishing between Uniform Resource Locator (U R L) vs. Uniform Resource Identifier (U R I).

 

URL plus the path = URI. If you do not do SSL decrypt, a Firepower or FTD sensor will not parse the path.

Thank You

Review Cisco Networking products for a $25 gift card