Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blacklisting webpage does not work.

Hello all,

Due to increased spam traffic with malicious links, we need to dynamically block certain URLs. With policy helpdesk, I can easily track what filter action and policy took place for particular user. I am conviced I blacklisted the webpage in the right place and yet, the user still can access the webpage. Below on the screenshots is outcome from particular policy, filter action and policy helpdesk test. Of course I had to cover texts that could lead to de-anonymization of the firewall, where screenshots were taken (hence there are some white rectangles in some parts of the screenshots). The images posted to my post have bad quality (you cannot read the setings), I therefore used external webpage for image hosting

What am I doing wrong?

 

Filter Action:

pasteboard.co/IDAeAfu.png

Policy test:

pasteboard.co/IDAeYbr.png

Profile:

pasteboard.co/IDAf4D2.png

 

Thank you in advance, take care.



This thread was automatically locked due to age.
  • Hello Douglas, hello all,

    first of all, I would like to thank you for sharing your ideas and valuable insights. It helped me to slow down and think more thoroughly. It was a stupid mistake that made earlier and I found it with fresh and rested brain. One of my exceptions had OR operators instead of AND operators. Basically - the exception ought to work like - if user is in that group and is accessing this domain, skip URL filter ... actually, the URL filter was skipped only based on the group membership (because of the OR operators and target domain was not taken into consideration.

    I am sorry for blaming the box for my mistake.

    Thank you everyone for your ideas, much appreciated!

    Request solved.