This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to block internet access and allow Face time application only.

Dear all,

Please share your expertise in following; 

 

How to block internet access and allow Face time application only on specific subnet using Sophos XG 230 firewall.  



This thread was automatically locked due to age.
Parents
  • Hi Shoukat Ali,

    You can block it via an Application Filter policy, you can check out the How-To videos for Web/App control here for configurations. You can also block it at the IP address level, if the application filter doesn't help.

    According to what I found, there are three ranges of IPs that iMessage/Facetime uses and needs to be allowed/blocked:
    17.173.0.1 to 17.173.255.255
    17.178.0.1 to 17.178.255.255
    17.133.0.1 to 17.133.255.255

    These are large IP ranges and likely contain services that you still want to use (ie. App Store). Here, explicitly ALLOW the following range to enable the App Store:
    17.173.65.1 to 17.173.65.255

    For this, you need to create a User/Network Rule, place it on the TOP and create new definitions/objects for IP ranges and add them in the Destination Networks option inside this new rule. Allow the action and it will do the job.

    You need another firewall rule with action defined as DROP and place it below the above mentioned rule with Source: ANY > Services ANY > Destination: ANY.

    Thanks,

  • Dear sachingurung,

     

    Please help in solving the above issue.

Reply Children