cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
937
Views
0
Helpful
5
Replies

RV345 Application Filtering

Terabyte
Level 1
Level 1

Testing the RV345 secuirty software, it seems that Application Filtering really doesn't do much at all once once leaves a browser.  For example, I have all News and Media blocked Amazon Instant Video blocked on a test policy but I'm able to fire up AP, Reuters, CNN, Google News, and Amazon Video on both an iPhone and an Android phone and access content without issues.  What am I mising or do users just get to easily bypass any filters by using an app on their phone rather than a broswer?

5 Replies 5

Glenn Martin
Cisco Employee
Cisco Employee

Walk me through your configuratoin. I take it your RV345 is in front of your wireless device/AP? 

 

Glenn

 

Yes, all News & Media blocked.  Device type is set to All.  Mobile browsers are blocked, but mobile apps get all the news they want.  Same holds true for Amazon Video.  The Amazon Video app is able to stream video even with it specifically blocked in the filters.

what Wireless device are you connected to, and where is it in your network?

We have 1 x WAP321 which is powered by an SG300-10P which connects to an SG300-28P which connects to the RV345.  Both switches are in Layer-2 mode.  We also have 2 x WAP371's powered by the SG300-28P; however, it should make no difference what APs we connect to, the filtering happens at the firewall.  I should be able to use the cheapest AP out there and it shouldn't matter, security services happen at the perimeter.  FWIW, all of our Cisco devices are on the latest firmware.  We'll do more testing tomorrow.  I'm happy to share the config files with you if that'd help.

Hi Terabyte,

No problem, I was just trying to understand your network and where in the network the RV345 was. You're right, the AP type doesn't matter as long as it's behind the RV345. I'll have to explore what might be happening here, however, if you have the capability you should open a case with the Technical Services team for further investigation. If I do find somehting out quickly I'll surely update you here.