Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Configure an Extended ACL for DNS and Web Traffic

Updated: February 5, 2026

Overview

Provides instructions to configure an extended access control list (ACL) to match DNS and web traffic and steer Threat Defense (FTD) internet-bound traffic through the intended egress path.

The access list is configured for DNS and web traffic to be steered towards the internet from the egress interface with the help of policy based routing.

Procedure

1.

Select Objects > Object Management and choose Access Lists > Extended from the table of contents.

2.

Click Add Extended Access List to create an extended access list for social media traffic.

3.

In the Extended ACL Object dialog box, enter a name (LAN_to_Internet) for the object.

4.

Click Add to create a new Extended Access List.

5.

Configure the following access control properties:

  1. Select the Action to Allow (match) the traffic criteria.

  2. Click the Port tab and search for HTTP, HTTPS, DNS_over_UDP, DNS_over_TCP in the Available Ports list.

  3. Select the ports and click Add to Destination.

  4. Click the Network tab and search for the branch LAN in the Available Networks list.

    Note

    In our example, the network is Branch-LAN.

  5. Select Branch-LAN and click Add to Source.

  6. Click Add to add the entry to the object.

  7. Click Save.

The ACL object is created as seen in the figure below.

Details of the ACL object