Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Same Websites blocked and allowed in wrong catagory

Hi, 

We have setup network DLP before the firewall which is connected like, Endpoint >> L2Switch >> Network DLP (centos uses Proxy) >> Sophos Firewall. 

For Example website Web.workline.hr

This website comes under the hrms category which is allowed in Sophos firewall. But sometimes this same website category gets changed to business category after it passes through NDLP server and is blocked by firewall as business category is not allowed by firewall as per firewall policy.

In the nutshell same website sometime shows in category A and sometime catagory B, when traffic flows through Network DLP server (network DLP uses it's own certificate for handshaking). 



This thread was automatically locked due to age.
Parents
  • When you say "this website comes under the hrms category" does that mean you have created a custom category for to match this website?

    If so, then the website is actually both "hrms" (your custom category) and "business" (the real category from cloud lookup).  It will match the first web rule for either traffic.

    So if your web rules are:

    Allow hrms
    Block business

    Then it will allow it and say that it is hrms.

    If your rules are:

    Block business
    Allow hrms


    It will block it and say it is business.


    Make sure that all the web policies you are using have rules that will apply to hrms first.

Reply
  • When you say "this website comes under the hrms category" does that mean you have created a custom category for to match this website?

    If so, then the website is actually both "hrms" (your custom category) and "business" (the real category from cloud lookup).  It will match the first web rule for either traffic.

    So if your web rules are:

    Allow hrms
    Block business

    Then it will allow it and say that it is hrms.

    If your rules are:

    Block business
    Allow hrms


    It will block it and say it is business.


    Make sure that all the web policies you are using have rules that will apply to hrms first.

Children
No Data