05-11-2023 02:33 AM
Hi Team,
May i know if we configure a Rule with certain unwanted URL Categories to Block on top of the rule base. Will it block only the categories and allow any other traffic from that rule?
05-17-2023 12:22 AM - edited 05-17-2023 01:43 AM
@ssan239 I think it's unlikely you are hosting phishing or spyware servers? In which case don't use "any" as the Source Zone, it's inefficient (as mentioned previously). You probably want a rule from Inside to Outside for URL filtering. Then inbound traffic from a public IP addressing will not match the URL filtering rule and be processed by another rule.
05-17-2023 03:45 AM
Thank you Rob,
True, but we do have remote access VPN setup so this has been implemented as Any Source Zone.
05-17-2023 04:15 AM
Hi Rob,
So does it mean it will allow traffic from out to In using this rule? We have Remote Access VPN users coming from outside so implementing the URL category rule for them will also can cause the issue is it?
Sorry for being a pain but trying to get more knowledge to follow the best practice.
05-17-2023 04:28 AM
@ssan239 if you don't specify source/destination zone and/or network and just on URL category, then that rule will be processed from any direction (inside to outside and vice versa and any other interface). If you want to follow the best practice, then as stated before don't use "any", specify the source/destination, therefore there is no ambiguity.
05-11-2023 05:21 AM
Thank you Very Much Rob for the clear explanation 🙂
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide