This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Policy and Filtering Not Working at All

XG V16 - It seems yet another thing real simple in other firewalls just doesn't want to work.  I'm not sure if the KB article I found isn't complete, but if I have the default web filtering policy or Default Workplace Policy applied on the only LAN-to-WAN network rule, nothing gets blocked, nor does anything show up in the log viewer.  Also, while I can see the value of doing it on a rule basis, is there a way to just filtering on a zone like with other firewalls?



This thread was automatically locked due to age.
Parents
  • David,

    Can you share the firewall page with all the rule?

    Thanks

  • Here it is.  The other Lan-to-Wan rules were added since this started, and most are currently disabled anyway.  Thanks.

  • Hi David,

    Take a look at #1 in my guide here and verify with the help of Packet Capture that which FW-rule does the traffic forwards through.

    I guess the traffic gets passed through Rule ID 25 which has no filters applied.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Okay, some strange behavior.  I got to the client site and oddly enough the filtering was working on one PC that it wasn't working on when I tested remotely last night, but it isn't working on another.  Further examination with the capture, and the one it isn't working on has a Business Rule to access it remotely via public IP, and the webfiltering is allowing passage based on an INBOUND rule, maybe because it is reflexive.  There is no option for a business rule to do web filtering. 

    The PC that is getting blocked has no unique rules for it, and is going out on the general LAN-to-WAN masquerade that other PCs are, rule 1, which has he wbe filtering policy.  Not idea why it is working this morning and not yesterday, but.....

    So, despite not being sure why the PAT'd PCs suddenly work, but how do you protect devices with a business rule?

    Also, from my original question, is there any way to blanket protect all devices in a zone, like in Sonicwall and others?  Doing it rule-by-rule has its place if you need the granularity, but I don't.

    Thanks.

  • Oh yes, forgot to mention that rule 25 that you questioned was disabled, though maybe tough to see in the screen shot.  Rule 1 was the first active LAN-to-WAN.

  • I would If I could attach images :-) 

    Sophos XG 450 (SFOS 18.5.1 MR-1)

    Sophos R.E.D 50 x 2

    Always configuring new stuff.....

  • Hi David,

    I completely missed to see that the FW-rule was disabled. Is the issue resolved? If not, try restarting the Web Proxy services from Administration> Services> Web proxy and also, show me a picture of drop-packet and packet filter logs. Next, go to Advance Shell and capture few log lines for awarrenhttp.log which states that the websites are allowed and filtering is not working.

    Last but not the least, check if the Web Protection license is active. 

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • Hi David,

    I completely missed to see that the FW-rule was disabled. Is the issue resolved? If not, try restarting the Web Proxy services from Administration> Services> Web proxy and also, show me a picture of drop-packet and packet filter logs. Next, go to Advance Shell and capture few log lines for awarrenhttp.log which states that the websites are allowed and filtering is not working.

    Last but not the least, check if the Web Protection license is active. 

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children
No Data