Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Not able to block facebook and other social Networks

XG125 (SFOS 17.5.12 MR-12) I created URL Group and Included facebook.com It didnt work it is applied with a Policy but the same policy does block other domains on the same list, after that tried with creating a Category same result doesnt block facebook then tried and active HTTP and HTTPS Inspection same result.

I have a Rule to test the policy applied to just one Host the rule is getting hit correctly I see it on the Log Viewer #17 the rule I created, I had to disable HTTPS inspection it was blocking almost any website almos any category which are not included Banks and News where generating errors blocking certains parts of the websites.



This thread was automatically locked due to age.
Parents
  • Upgraded to Version 19 still nothing it doesnt block Facebook

    Created a Application Filter including everything that mentioned Facebook

    Applied the Application Policy to the Rule, I can see all the traffic hitting correctly Rule 13 which has the BlockApplication (Facebook)

    but Still doesnt block anything Facebook website opens without any issue.

  • Hi,

     a couple of suggestions for your rule,

    1/. you need to enable block QUIC

    2/. You are using the Proxy even though you don't have the box ticked because you are scanning http and decrypted https.

    3/. the DPI does not in its current version scan UDP traffic

    4/. change the IPS to LAN to WAN, I found that improved my detection of applications etc I want to block

    5/. if you plan to use the DPI then you need to review the default exceptions in the SSL/TLS policies.

    6/. you will also need to decrypt HTTPS which means you will need to install the XG CA on the end user devices.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi,

     a couple of suggestions for your rule,

    1/. you need to enable block QUIC

    2/. You are using the Proxy even though you don't have the box ticked because you are scanning http and decrypted https.

    3/. the DPI does not in its current version scan UDP traffic

    4/. change the IPS to LAN to WAN, I found that improved my detection of applications etc I want to block

    5/. if you plan to use the DPI then you need to review the default exceptions in the SSL/TLS policies.

    6/. you will also need to decrypt HTTPS which means you will need to install the XG CA on the end user devices.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children