Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Content filter no longer working

I adjusted Default Content Filter action to prevent Nudity sites from being accessible with success a couple years ago.  However, I checked the other day, and even though my setting are still intact, I am able to access Nudity sites.  If I use the policy test option, it says "blocked" as it should.  But, again, I am able to open a browser and access Nudity sites.  This feature was working perfectly last year.  Not sure when it stopped.  Suggestions?



This thread was automatically locked due to age.
Parents
  • Patrick, show us the line from the Web Filtering log file where traffic was allowed that should have been blocked.

    Cheers - Bob
    PS Moving this to the Web Protection forum.

  • 2018:07:26-06:02:23 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="confd_config_filter" file="confd-client.c" line="3837" message="failed to resolve passthrough6.fw-notify.net, using 2a01:198:200:680::8080"
    2018:07:26-06:02:24 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="confd_config_reload_func" file="confd-client.c" line="651" message="reloading config done, new version 13163"
    2018:07:26-06:07:34 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="aptp_reload" file="aptpscanner.c" line="142" message="reloading ATP pattern"
    2018:07:26-06:07:35 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="aptp_reload" file="aptpscanner.c" line="160" message="reloading ATP pattern finished"
    2018:07:26-07:02:25 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="confd_config_reload_func" file="confd-client.c" line="587" message="reloading config"
    2018:07:26-07:02:26 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="parse_address" file="util.c" line="540" message="getaddrinfo: passthrough6.fw-notify.net: Name or service not known"
    2018:07:26-07:02:26 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="confd_config_filter" file="confd-client.c" line="3837" message="failed to resolve passthrough6.fw-notify.net, using 2a01:198:200:680::8080"
    2018:07:26-07:02:26 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="confd_config_reload_func" file="confd-client.c" line="651" message="reloading config done, new version 13172"
    2018:07:26-07:07:35 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="aptp_reload" file="aptpscanner.c" line="142" message="reloading ATP pattern"
    2018:07:26-07:07:37 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="aptp_reload" file="aptpscanner.c" line="160" message="reloading ATP pattern finished"
    2018:07:26-08:02:27 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="confd_config_reload_func" file="confd-client.c" line="587" message="reloading config"
    2018:07:26-08:02:28 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    +function="parse_address" file="util.c" line="540" message="getaddrinfo: passthrough6.fw-notify.net: Name or service not known"
    2018:07:26-08:02:28 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="confd_config_filter" file="confd-client.c" line="3837" message="failed to resolve passthrough6.fw-notify.net, using 2a01:198:200:680::8080"
    2018:07:26-08:02:29 sophos httpproxy[3998]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)"
    function="confd_config_reload_func" file="confd-client.c" line="651" message="reloading config done, new version 13183"
     
     
  • This line is a problem

    failed to resolve passthrough6.fw-notify.net, using 2a01:198:200:680::8080

    These addresses are supposed to point to UTM or point through UTM to an internet address at Sophos so that Sophos can interecept them.

     

    If you alllow the address to flow through to internet DNS, it should resolve to a non-working address at Sophos, on the assumption that it will cause the packet to flow toward your UTM where it can be intercepted.   If your UTM is not in the path to the internet, create a DNS entry that resolves that address to your UTM.

  • I think that's unrelated to Patrick's issue, Doug.  I think that's just the proxy starting and confd_config_filter complaining that IPv6 isn't activated.

    Patrick, we still haven't seen any proof that the traffic you're seeing not-blocked is even passing through Web Filtering. In fact, your log shows two hours with not one web request appearing. Is 192.168.1.137 in one of the subnets in 'Allowed Networks' for any Web Filtering Profile?  If so and that Profile is in Standard mode, is your browser configured to use the proxy?

    Cheers - Bob

  • This reply was deleted.
  • "I am set to standard operation mode."

    OK, so let's see what you get when you click on [Settings] at the bottom of the page 'Tools' 'Options' in Firefox.  If you have selected 'Use system proxy settings', then also show us [LAN Settings] at the bottom of the 'Connections' tab in 'Internet Options' in 'Control Panel' in Windows.

    Cheers - Bob

Reply
  • "I am set to standard operation mode."

    OK, so let's see what you get when you click on [Settings] at the bottom of the page 'Tools' 'Options' in Firefox.  If you have selected 'Use system proxy settings', then also show us [LAN Settings] at the bottom of the 'Connections' tab in 'Internet Options' in 'Control Panel' in Windows.

    Cheers - Bob

Children