This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocking Cloud Drives Except For OneDrive Failed Using Application Filter

To Whom It May Concern

I've been trying to block all cloud storage drives accessed from our corporate network except for OneDrive. I tested the implementation using my personal iCloud account after the implementation on our Sophos XG firewall of the Application Filter (please see attached screen shot of the application filter) and could access iCloud despite the application filter having been applied. I followed the instructions on your corporate support site link https://support.sophos.com/support/s/article/KB-000035682?language=en_US for Google Drive which stated it could be used for all cloud drives. Could you please help?

yours sincerely

Craig Hoy



This thread was automatically locked due to age.
Parents
  • Hi Craig,

    using logviewer filter on your PCs IP address and see which rules are used when accessing iCloud.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • I can't SSH to my firewall as I don't have the rights. Is there any other way that I can check the logs?

  • Hi,

    you are an admin. You do not need to ssh in but use the GUI.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • I had a look at the logs and noticed that the NAT rule allowed the ICloud to be accessed. How do I change the NAT rule to block Cloud drives without impacting other applications?

  • Hi,

    the NAT rule is not the issue, but a firewall rule you have is allowing the icloud access, which firewall rules was being used?

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • The firewall rules that were being used were the default rules. There weren't any rules that were customised.

    yours sincerely

    Craig Hoy

  • Hi Craig,

    there are no default allow rules, only block rules.

    If you are using the rules created at install time then they are very generic and provide open access, but they are not default.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • What I define as being default are the out of the box rules or what you call the generic rules. Is the allowance of iCloud and other Cloud Based Storage such as DropBox normal for Sophos XG firewalls?

  • If you are using the rules that are configured when you install the software and answer yes to the questions, then the rules will allow everything out.

    the basic rules are to allow you to have basic functions on your network while you build and tighten your firewall security.

    you cannot filter applications unless you are using the http proxy with decrypt and scan and allow all if you have applied your modified policy as shown above to the default policy.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Then how do I block cloud storage? This is what I originally asked. I wanted to block all cloud storage except for OneDrive which we use for our corporate storage.

  • Please post a copy of your firewall rules.

    do you use decrypt and scan, have you installed cas on the devices?

    Thingsyou will need to change

    1/. change any service to s specific range of services in all rules

    2/. build you own application policies  to be applied to firewall rules

    3/. you will need to use web, application and IPS.

    4/.there is a KBA on how to block VPNs, that would be a good place to start.


    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Please post a copy of your firewall rules.

    do you use decrypt and scan, have you installed cas on the devices?

    Thingsyou will need to change

    1/. change any service to s specific range of services in all rules

    2/. build you own application policies  to be applied to firewall rules

    3/. you will need to use web, application and IPS.

    4/.there is a KBA on how to block VPNs, that would be a good place to start.


    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children