NGAF - Rules pointing to a FQDN
  

ThomasC Lv1Posted 2024-Nov-04 19:20

Good day to all,
   I need to configure a rule in NGAF pointing to a FQDN; I cannot find where (and if) it's possible to do that.

I've tried to create an alias (network object) pointing to some IP, but I grant for sure that this IP will change on a regular basis and it's quite a task ora rather impossible to maintain this "solution".

Any help would be great!

Thanks for your attention, have a great day,
   Thomas
ThomasC Lv1Posted 2024-Nov-04 21:16
  
Hi all,
I think I've found the culprit for the 8.0.17 version:

System -> Network -> Enable application control based on domain name

I'll try to find this option for the latest 8.0.47.

Thomas
Enrico Vanzetto Lv4Posted 2024-Nov-04 22:45
  
Hi, i suggest you to create a network object about your domain by specifying the fqdn. After that, you can create an application control rule to grant traffic to. Here you can find a lot of useful guides (replace xx with tt to make link clickable): hxxps://knowledgebase.sangfor.com/indexPage?module=601
ThomasC Lv1Posted 2024-Nov-04 22:46
  
NGAF 8.0.17

For future reference of other and for future me also.

If you enable the above, in the L3 portion of the firewall, there is a new item inside the Destination/Address, labeled "Domain Name" where you can put FQDN; I've attached a screenshot of it after enabling it.

Policies -> Access Control -> Application Control

Note, that this works for outgoing traffic only.

I'll try, as soon as I have an 8.0.47 on hand, to check this on the latest and supported FW (as of today).

Thomas

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
ThomasC Lv1Posted 2024-Nov-04 23:12
  
NGAF 8.0.47

You can definetly do it for the 8.0.47, the path to enable the DNS app control:

System -> General Settings -> Network -> Business Asset/User Security Page Display Settings -> Enable application control based on domain name

Attached, the screenshot of the App Control page regarding the DNS feature.

It would be cool if there was an option similar to an alias (network object) for DNS names.

Thomas

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Shared by Author