dynamic block lists / access groups with FQDN support

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

dynamic block lists / access groups with FQDN support

L2 Linker

Currently we have this security policy to allow FTP access. A user who needs FTP access must be part of a special AD group and the FTP server must be part of an address group.

FTP.png

The problem is that there are a lot of changes and the responsible person does not have access to the firewall. This should not be changed.

So my idea was to use dynamic block lists or dynamic address groups. But I think they support only IPs. Is there a possibility to use FQDN? If not can you tell me another alternative how to reach my goal?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi

if changing the security policy each time is not an option you could either try to set up a dynamic address group which you can alter by using API calls:

How to Add an IP Address to a Dynamic Address Group using API

or set up a domain on your internal DNS server where you can change/add the IP addresses as needed (each fqdn object can contain up to 10 ip addresses)

the dynamic address group will probably be the best solution

regards

Tom

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

Hi

if changing the security policy each time is not an option you could either try to set up a dynamic address group which you can alter by using API calls:

How to Add an IP Address to a Dynamic Address Group using API

or set up a domain on your internal DNS server where you can change/add the IP addresses as needed (each fqdn object can contain up to 10 ip addresses)

the dynamic address group will probably be the best solution

regards

Tom

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 2465 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!