09-18-2023 06:25 AM
Hello everyone,
I got an issue with FTD filtering based on URL rules (predefined categories).
I have some rules that blocks sites with adult content, gambling, video games and other categories:
Some of sites are blocked and I got ERR_CONNECTION_RESET, so it's working fine, but a lot of websites are still accessible, even if Connection Events says it's blocked based on ACP:
I made a rule for this website in screenshot based on it's URL, but it's still working. After this, I banned it's IP addresses, and it stopped working (rule worked fine).
Can someone explain me why FTD does not block websites, but sends logs that it's blocking?
09-18-2023 07:49 AM
If you looking to Block ( select Block) rather Block with reset
more informaion explained here block and block with reset (other options)
09-19-2023 04:05 AM
I've tried both ways, but the sites are still available, although in connections events I see that it have been blocked based on rule (for example Gambling)
09-19-2023 04:24 AM
Could it be the sites you tested were cached on the endpoint you tested from? if you try to ping one of those URL's would you get any responses?
09-19-2023 04:39 AM
I've accessed these pages from many workstations, also cleared cache. And yes, I get icmp responses, also telnet on 80/443 is ok. So, FTD does not block traffic
09-19-2023 05:15 AM
Add dns server IP to ftd' make sure ftd can resolve the ip.
09-19-2023 05:51 AM
There's already DNS servers. The problem is that some of sites are blocked, and some are not, although in connections events I can see that FTD kind restricted access (it didn't).
09-19-2023 06:09 AM
Some sites block some not'
Check site allow is bypass by prefilter acl or it already have conn.
If it have conn try clear conn and check again.
09-19-2023 06:57 AM
I've just accessed 1xbet.com (gambling site), it works fine, but conn events says that it's blocked (and one line that it's uncategorized and allowed).
09-20-2023 05:11 AM
Dumb question.. Did you deploy?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide