Start a conversation

Using a Network Object to Block a URL

Overview

You created a FQDN (Fully Qualified Domain Name) network object to block access to a URL but are still able to access the URL. The optimizer is on and the policies are set to correct URL as in the screenshots below. 

Optimizer.pngPolicy.png2021-09-21_23_02_16-Clipboard.png

Solution

  1. Follow this article to create FQDN based network objects
  2. After creating the FQDN, check if there is an IP/subnet for the object. If there is no IP address, using the object in the policy will not work as expected
    Solution_1.png

    If there are no subnets, this means the DNS you set failed to resolve this or there might have been a temporary issue resolving the URL
  3. Check if the network object has an IP address and DNS now. Use the following commands to check if the configuration is correct:
    network-object <test_object> fqdn <URL>
    show network-object <test_object>
    Solution_2.png
  4. Resolve DNS problems with your Network team if FQDN URL still fails to resolve.

 

Testing

Check that the FQDN network object successfully blocks the configured URL

Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted
  3. Updated

Comments