Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocking all connectivity by time of day

So, I want to be able to stop my child using his smart tv to access Netflix at night time.

Web filtering is on, but the TV is in the skip list.

Setting a firewall rule does nothing, even if I set it to drop all traffic without a time of day that is destined for his (or any other) host, traffic still flows, as though allow rules take priority.

Even if I turn off web filtering, the firewall rule still doesn't work.

I can't use a NAT rule to black hole it as this can't be done based on time of day.

 

Why is this so complicated? Any pointers?



This thread was automatically locked due to age.
Parents
  • Hi Richard,

    A Drop Firewall Rule will not be effective configuration here as we are looking at HTTP/S traffic which are processed by Web Proxy. To drop the traffic you must first, skip the source traffic from the transparent proxy. To do that, go to Web Filter | Filtering Option | MISC | Skip Transparent Proxy | Add the source IP of TV in Skip Transparent Mode Source Hosts/Nets. Uncheck "Allow HTTP/S traffic for listed hosts/nets" and then create a rule

    Source(x.x.x.x source IP of TV) > ANY > Destination(Internet IPv4) > Drop > Time Schedule. 

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • Hi Richard,

    A Drop Firewall Rule will not be effective configuration here as we are looking at HTTP/S traffic which are processed by Web Proxy. To drop the traffic you must first, skip the source traffic from the transparent proxy. To do that, go to Web Filter | Filtering Option | MISC | Skip Transparent Proxy | Add the source IP of TV in Skip Transparent Mode Source Hosts/Nets. Uncheck "Allow HTTP/S traffic for listed hosts/nets" and then create a rule

    Source(x.x.x.x source IP of TV) > ANY > Destination(Internet IPv4) > Drop > Time Schedule. 

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children