We have IPS sensors on each of our corporate office and we want to make sure the VOICE service (SaaS, in the cloud). The vendor provides a number of URLs that must be excluded from inspection (cant provide IPs because the can constantly change).
From the Policy TAB, I crated a RULE OBJECT of the "Host DNS Name" type and added all the given URLs to it. The used this new object in the Firewall policy and told it to IGNORE this traffic.
I am not in a position to test this yet, but can somebody at McAfee confirm if "Host DNS Name" is the appropriate way to exclude URLs? (I.e. meet.google.com)
Solved! Go to Solution.
That's the correct method you are following to ignore domains using firewall rule.
You can create the list of source and destination hostnames that you want to use in
a Firewall rule. The Sensor contacts the DNS servers that you configure to resolve these names to IP
addresses. For example, you can create a Host DNS Name rule object for facebook.com, faceparty.co.uk,
ibibo.com. You can add 10 Host DNS Names in a rule object.
Please Note: The Sensor uses only UDP and never falls back to TCP for DNS queries even if the DNS server forces for TCP.
Regards,
Faizan
That's the correct method you are following to ignore domains using firewall rule.
You can create the list of source and destination hostnames that you want to use in
a Firewall rule. The Sensor contacts the DNS servers that you configure to resolve these names to IP
addresses. For example, you can create a Host DNS Name rule object for facebook.com, faceparty.co.uk,
ibibo.com. You can add 10 Host DNS Names in a rule object.
Please Note: The Sensor uses only UDP and never falls back to TCP for DNS queries even if the DNS server forces for TCP.
Regards,
Faizan
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA