02-27-2017 05:10 PM - edited 03-12-2019 06:18 AM
Hello,
So i setup a rule to only allow category "search engines" and block everything else.
After applying it, i am able to browse to google.com and i get blocked from news websites etc.. so working as expected.
But i am able to browse to google drive - which is wrong.
According to Firesight its listed as "Personal Storage", but when I go to Analyse, Connection, Events, its listing as "Search Engines".
Any help with this is appreciated.
Firesight - 6.2.0
Firerpower - 6.2.0-362
DNS resolving on both boxes and i can see the latest ruleset downloaded.
Ivan.
03-01-2017 07:02 PM
Perhaps create a rule to try allowing Google Drive explicitly.
03-02-2017 02:18 AM
So the work around was to put a rule in before the permit 'search engine' category to block URL drive.google.com.
But this should not have to be done because google drive is not a search engine.
03-02-2017 01:00 PM
The URL filtering service it from Webroot. You can lookup the URL here.
On that website I am told that the URL "drive.google.com" is in the category "Personal Storage", as expected.
http://www.brightcloud.com/tools/url-ip-lookup.php
03-02-2017 01:19 PM
I understand that, even the Firesight console reports it as personal storage when doing a category check.
What I don't understand is why it comes up under event viewer as search engine.
03-02-2017 01:19 PM
It does sound like a bug. Maybe you should have Cisco TAC take a look at it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide