0% found this document useful (0 votes)
4 views6 pages

37 URL++Filtering+Lab

The document outlines the process for setting up URL and web category filtering using Default Access Control policies. It details the creation of four rules to block categories such as Games, Gambling, Malware, Streaming, Shopping, and Job Search, along with logging settings. Verification steps are also provided to ensure the filtering is functioning correctly on a specified internal LAN PC.

Uploaded by

MonkeyAhihi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views6 pages

37 URL++Filtering+Lab

The document outlines the process for setting up URL and web category filtering using Default Access Control policies. It details the creation of four rules to block categories such as Games, Gambling, Malware, Streaming, Shopping, and Job Search, along with logging settings. Verification steps are also provided to ensure the filtering is functioning correctly on a specified internal LAN PC.

Uploaded by

MonkeyAhihi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

URL and Web Category Filtering:

Action Source Destination


Block with Reset LAN Subnet Category: Games, Gambling, Malware
Block LAN Subnet Category: Streaming and Shopping
Interactive Block LAN Subnet Category: Job Search
Block with Reset LAN Subnet Reputations: High Risk

Go to Policies > Access Control > Default Access Control. We already have the Default Access
Control policy in which we have to create a rule for Games, Gambling and Malware category.
Provide name Block-Reset Category 1 and set action to Block with Reset.
Under URLs tab > type/search for the specific Category (Gambling, Games and Malware Sites in
this case) > leave Reputations of Any > click Add to Rule to move under Selected URLs on the
right column.

1 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717


Select Logging at Beginning of Connection > click Add.

We already have the Default Access Control policy in which we have to create another rule for
Streaming Media, and Shopping category. Provide name Block Category 2 and set action to
Block.
Under URLs tab > type/search for the specific Category (Streaming Media and Shopping in this
case) > leave Reputations of Any > click Add to Rule to move under Selected URLs on the right
column.

Select Logging at Beginning of Connection > click Add

We already have the Default Access Control policy in which we have to create 3rd rule for Job
Searching Website category. Provide name Int Block Category 3 and set action to Interactive
Block.
Under URLs tab > type/search for the specific Category (Job Search in this case) > leave
Reputations of Any > click Add to Rule to move under Selected URLs on the right column.

2 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717


Select Logging at Beginning of Connection > click Add

We already have the Default Access Control policy in which we have to create 4th rule for High
Riske Reputations category. Provide name Int Block-Reset Category 4 and set action to Block
with reset.
Under URLs tab > type/search for the specific Category (Any in this case) > choose Reputations
of 1- High Risk > click Add to Rule to move under Selected URLs on the right column.

Select Logging at Beginning of Connection > click Add

3 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717


Finally, all four rules have been created showing below in the screenshot.

Click Save (disk icon) > Deploy (beside System) > select device > Deploy.

Click the check (green icon) Message Center to view Deployment Status.

4 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717


Verification and Testing:
Let’s check and verify that whatever URL filtering that we have created is actually working. Go to any
Internal LAN subnet PC in this case PC2 with IP Address [Link].

Visiting [Link] which fall under Games Category it has been blocked by FTD.

Visiting [Link] which fall under Gambling Category it has been blocked by FTD.

Visiting [Link] which fall under Malware Category it has been blocked by FTD.

Visiting [Link] which fall under Shopping Category it has been blocked by FTD.

5 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717


Visiting [Link] which fall under Job Search Category it has been interactive blocked by
Cisco Firepower Thread Defense (FTD) with Continue button.

You can view Event logs under Analysis > Connections >Events.

6 | P a g e Created by Ahmad Ali E-Mail: ahmadalimsc@[Link] , Mobile: 056 430 3717

You might also like