05-04-2017 06:16 AM - edited 03-12-2019 06:23 AM
Does anyone have any reccomendation on which categories they filter on and by reputation level? The problem I am having as a consultant is defining which categories the business should have in place. I wish it was as simple as adding all categories high risk but that may cause some issues.
05-05-2017 01:56 PM
Hey Keith,
We just set this up in our office and with a bit of trial and error we using the following categories with any reputation:
From here, we allow sites on an exception basis. We have a link to our internal ticketing system in our HTTP Response block page and request users provide a business need from that point. The main reasons for the categories are productivity and risk based while trying to strike a balance for "incidental" usage. This is still a work in progress, there are other categories we are still considering. If I was using categories, I would probably set most to block anything with a rating of 1, 2, or 3.
If the business has a defined Rules of Behavior or Acceptable Use Policy that would be a great launching point for you to start defining categories that match the business' needs and are enforceable through policy.
As a side note. be very careful with the Web Advertisements category, if it is set to any reputation, it can end up blocking pretty much every site you try to visit.
Hope that helps.
05-05-2017 08:01 PM
That's a great approach.
I would only add that the Personal storage category may not always be appropriate - it includes things like Dropbox, OneDrive and Box.com which may be approved for use in many enterprises.
If in doubt about a particular site, you can always check the category via the Brightcloud lookup tool:
http://www.brightcloud.com/tools/url-ip-lookup.php
That's what FirePOWER currently uses for URL categories.
05-08-2017 06:28 AM
This is great info guys. Very much appreciated!!! It is nice to be able to lean on those who have the knowledge. I just don't have enough yet to share and help others out like you guys have. It really has been a pleasure to read through replies such as Marvin's as without people like him to share it would be very hard on someone as myself to take on Firepower alone.
07-10-2018 08:36 AM
Hi Marvin
Does FirePower still uses brightcloud?
I currently have a example where the category differs:
Cisco SFR: Adult and Pornography
BrightCloud: Business and Economy
kind regards
Tobias
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: