Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Application control blocking websites

Hi,

one of our customer was trying to browse "https://apex.irclass.org:82 " but failed. I have allowed the fqdn and found nothing wrong logs in web filtering and application control logs. When i removed the application control, start getting the traffic.

Anyone can guide:

1. How to get the logs related to this issue.

2. How to allow "https://apex.irclass.org:82" in application control

Thanks in Advance



This thread was automatically locked due to age.
Parents
  • Application Control looks at things like destination ports, and port 82 is totally non-standard for HTTPS, so that's a plausible reason. (In fact, 81, 82, etc, seem to be used by some TORs, which would be suspicious.)

    When I try going to that link, entries show up in Log Viewer > Application Filter identifying it as a TOR Proxy, which makes sense. It gives a Policy ID of 4 and App Filter Policy ID is 8, though I'm not sure what to do to locate that and turn it off in Application Filtering.

    Worst-case, you could set up a firewall rule that has no App Filtering with destination of that particular domain, destination port 82. Make sure it's higher than the rules messing you up.

  • Thanks for the reply ! Through that process only im allowing the current traffic. Is it the standard way or there are anything else inside application filtering to  allow these non standard traffic? 

Reply Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?