This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Exceptions rules for Application Filter

I'm facing an issue with false positive of the Application Filter on SFOS 16.05.03 MR-1 accessing a legit web site.
Here the relevant log from console:

device="SFW" date=2017-05-03 time=12:32:18 timezone="CEST" device_name="CR1500iNG-XP" device_id=CXXXXXXXXX-XXXXXX log_id=054402617051 log_type="Content Filtering" log_component="Application" log_subtype="Denied" priority=Information fw_rule_id=10 user_name="xxxxx@xxxxxxx" user_gp="grp-xxxxxxxx" application_filter_policy=11 category="Proxy and Tunnel" application_name="WebFreer Proxy" application_risk=3 application_technology="Browser Based" application_category="Proxy and Tunnel" src_ip=xx.xx.xx.xx src_country_code=ITA dst_ip=xx.xx.xx.xx dst_country_code=R1 protocol="TCP" src_port=443 dst_port=53002 sent_bytes=0 recv_bytes=0 status="Deny" message=""

The only known workaround to avoid this false positive is to create a destination based firewall rule for that particular site with no Application Filter (or specifically modified Application Filter policy).
That is not a good solution in my particular scenario because I have many different user groups, each one with a specific Web Filter and Application Filter policies, and some of the groups do not even have to access that legit web site, so it is required to create many different destination based rules.

So, my suggestion is that it could be far better to have an Application Filter Excepetions similar to the one for the Web Filter.



This thread was automatically locked due to age.
Parents
  • Sorry for replying to such an old post, however I've just come across this issue, and this thread ranks highly on Google when trying to investigate it. I thought I'd share my workaround in case other people have the same issue:

     

    On v17 (17.0.3 at the time of writing) You can add work around this by editing the Application Filter that is in use, and added the particular application as a specific "Allow" above those that are denied, as per this screenshot:

    In your case, you would add the Application "WebFreer Proxy"

    Hope this helps future internet people!

    Dave

  • I can confirm as of version 17.0.6 MR-6 if I block for example, Application level 5 threats to include P2P it will kill all Hi-Rez Paladins games as they use that protocol.  I've tried monitoring the logs and adding "Policy" exceptions for the IP addresses I've discovered it is only partially successful - about 50% of the traffic gets blocked and 50% approved.  In my understand this is a **BUG**

    Similarly my Verizon Samsung Galaxy keeps reaching out to two addresses:  141.207.137.232 and 141.207.139.232   I've made a Web/Policy Exception called Verizon Wireless and included those two addresses but still find them occasionally blocked when I check the Application Filter Log.

    Unless I create a LAN to LAN firewall rule above my primary LAN to WAN rule with no application filter policies just for these address or except the **entire category** of Torrent Clients P2P I cannot get the traffic to flow smoothly.  Since I do not want Torrent Clients P2P traffic on my network the firewall rule seems to be the only choice to maintain security and 100% success of applying my policy exceptions.
     
    For those looking for permanent answers I was specifically searching for "sophos xg policy exception to application control"
     
Reply
  • I can confirm as of version 17.0.6 MR-6 if I block for example, Application level 5 threats to include P2P it will kill all Hi-Rez Paladins games as they use that protocol.  I've tried monitoring the logs and adding "Policy" exceptions for the IP addresses I've discovered it is only partially successful - about 50% of the traffic gets blocked and 50% approved.  In my understand this is a **BUG**

    Similarly my Verizon Samsung Galaxy keeps reaching out to two addresses:  141.207.137.232 and 141.207.139.232   I've made a Web/Policy Exception called Verizon Wireless and included those two addresses but still find them occasionally blocked when I check the Application Filter Log.

    Unless I create a LAN to LAN firewall rule above my primary LAN to WAN rule with no application filter policies just for these address or except the **entire category** of Torrent Clients P2P I cannot get the traffic to flow smoothly.  Since I do not want Torrent Clients P2P traffic on my network the firewall rule seems to be the only choice to maintain security and 100% success of applying my policy exceptions.
     
    For those looking for permanent answers I was specifically searching for "sophos xg policy exception to application control"
     
Children
No Data