update wsus server via asa 5505 using domain names?

We have a requirement for a WSUS server to receive updates which sits behind a ASA5505.  I understand to enable this to happen the WSUS server needs to communicate with many DNS names and therefore there are many potential IP addresses/ranges that the ASA needs to apply the appropriate security policy too. An example of just a few of the DNS names we need to apply a security policy to are http://windowsupdate.microsoft.com, http://*.windowsupdate.microsoft.com, https://*.windowsupdate.microsoft.com etc etc....

Is it possible to apply a security policy based on domain names as apposed to IP address/ranges on a ASA5505?

Who is Participating?
Pete LongConnect With a Mentor Technical ConsultantCommented:
If you mean ACL and modular policy frameworks, then no you cannot - the ASA is concerned with IP addresses not  hostnames or URL's - sorry :(
mtuttonAuthor Commented:
Thanks for your response.

Pete LongTechnical ConsultantCommented:
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.