URL and Web Category Filtering:
Action Source Destination
Block with Reset LAN Subnet Category: Games, Gambling, Malware
Block LAN Subnet Category: Streaming and Shopping
Interactive Block LAN Subnet Category: Job Search
Block with Reset LAN Subnet Reputations: High Risk
Go to Policies > Access Control > Default Access Control. We already have the Default Access
Control policy in which we have to create a rule for Games, Gambling and Malware category.
Provide name Block-Reset Category 1 and set action to Block with Reset.
Under URLs tab > type/search for the specific Category (Gambling, Games and Malware Sites in
this case) > leave Reputations of Any > click Add to Rule to move under Selected URLs on the
right column.
1 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717
Select Logging at Beginning of Connection > click Add.
We already have the Default Access Control policy in which we have to create another rule for
Streaming Media, and Shopping category. Provide name Block Category 2 and set action to
Block.
Under URLs tab > type/search for the specific Category (Streaming Media and Shopping in this
case) > leave Reputations of Any > click Add to Rule to move under Selected URLs on the right
column.
Select Logging at Beginning of Connection > click Add
We already have the Default Access Control policy in which we have to create 3rd rule for Job
Searching Website category. Provide name Int Block Category 3 and set action to Interactive
Block.
Under URLs tab > type/search for the specific Category (Job Search in this case) > leave
Reputations of Any > click Add to Rule to move under Selected URLs on the right column.
2 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717
Select Logging at Beginning of Connection > click Add
We already have the Default Access Control policy in which we have to create 4th rule for High
Riske Reputations category. Provide name Int Block-Reset Category 4 and set action to Block
with reset.
Under URLs tab > type/search for the specific Category (Any in this case) > choose Reputations
of 1- High Risk > click Add to Rule to move under Selected URLs on the right column.
Select Logging at Beginning of Connection > click Add
3 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717
Finally, all four rules have been created showing below in the screenshot.
Click Save (disk icon) > Deploy (beside System) > select device > Deploy.
Click the check (green icon) Message Center to view Deployment Status.
4 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717
Verification and Testing:
Let’s check and verify that whatever URL filtering that we have created is actually working. Go to any
Internal LAN subnet PC in this case PC2 with IP Address [Link].
Visiting [Link] which fall under Games Category it has been blocked by FTD.
Visiting [Link] which fall under Gambling Category it has been blocked by FTD.
Visiting [Link] which fall under Malware Category it has been blocked by FTD.
Visiting [Link] which fall under Shopping Category it has been blocked by FTD.
5 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717
Visiting [Link] which fall under Job Search Category it has been interactive blocked by
Cisco Firepower Thread Defense (FTD) with Continue button.
You can view Event logs under Analysis > Connections >Events.
6 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717