A firewall can control traffic based on IP addresses, ports, zones, and sometimes applications. That is useful, but it still does not fully answer one simple question: Where is the user really going on the Internet?
All websites use the same common port, typically HTTPS (TCP port 443). From the firewall’s point of view, all of that traffic can look the same. On the other hand, most attacks begin when a user visits a malicious website even without their knowledge. For example, an email redirects the user to a fake copy of a trusted site. From there, the attack may steal credentials, deliver malware, and so on. That’s why security teams need URL filtering.
The security team wants the network to block access to phishing or newly registered suspicious domains, way before real damage is already done. URL filtering adds web awareness to the security policy.
The Cisco SD-WAN URL Filtering (URLF) feature allows edge devices to inspect HTTP/HTTPS traffic and enforce URL-based control. URLF leverages the Security Virtual Image required for security capabilities such as IPS, and Advanced Malware Protection (AMP) on IOS-XE routers. The following diagram illustrates the URL Filtering process.
Digital Book Access
For now, the digital version of this book is available only to active subscribers and readers who own a paperback copy.
The ability to buy the digital copy directly is coming soon.
- Subscribers can access the full digital version as part of their membership.
- Paperback owners can access the digital version using the instructions provided in the book.