cancel
Showing results for 
Search instead for 
Did you mean: 
Reliable Contributor kylekat
Reliable Contributor
Report Inappropriate Content
Message 1 of 2

Recommended process to exclude URLs from inspection in IPS sensors

Jump to solution

We have IPS sensors on each of our corporate office and we want to make sure the VOICE service (SaaS, in the cloud). The vendor provides a number of URLs that must be excluded from inspection (cant provide IPs because the can constantly change).

From the Policy TAB, I crated a RULE OBJECT of the "Host DNS Name" type and added all the given URLs to it. The used this new object in the Firewall policy and told it to IGNORE this traffic.

 

I am not in a position to test this yet, but can somebody at McAfee confirm if "Host DNS Name" is the appropriate way to exclude URLs? (I.e. meet.google.com)

1 Solution

Accepted Solutions
McAfee Employee fkazi04
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: Recommended process to exclude URLs from inspection in IPS sensors

Jump to solution

That's the correct method you are following to ignore domains using firewall rule.

You can create the list of source and destination hostnames that you want to use in
a Firewall rule. The Sensor contacts the DNS servers that you configure to resolve these names to IP
addresses. For example, you can create a Host DNS Name rule object for facebook.com, faceparty.co.uk,
ibibo.com. You can add 10 Host DNS Names in a rule object. 

Please Note: The Sensor uses only UDP and never falls back to TCP for DNS queries even if the DNS server forces for TCP.

Regards,

Faizan

Regards,
Faizan

Was my reply helpful?
If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
1 Reply
McAfee Employee fkazi04
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: Recommended process to exclude URLs from inspection in IPS sensors

Jump to solution

That's the correct method you are following to ignore domains using firewall rule.

You can create the list of source and destination hostnames that you want to use in
a Firewall rule. The Sensor contacts the DNS servers that you configure to resolve these names to IP
addresses. For example, you can create a Host DNS Name rule object for facebook.com, faceparty.co.uk,
ibibo.com. You can add 10 Host DNS Names in a rule object. 

Please Note: The Sensor uses only UDP and never falls back to TCP for DNS queries even if the DNS server forces for TCP.

Regards,

Faizan

Regards,
Faizan

Was my reply helpful?
If you find this post useful, please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community