07-31-2025 09:57 AM
Hello Professionals,
I'm trying to start wireless traffic control, what I want to implement is 'Drop packets for specific URL access'.
First trial was 'URL filtering'. I configured and typed
*.indeed.com
www.indeed.com
It seems working good, and I applied this rule for all of my WLANs. However, it sometimes works, sometimes don't.
When try nslookup from test PC to indeed.com, it redirects the IP address what I configured, but still I was able to reach.
I could've cleared caches from browsers, but I don't think it is enough.
Second trial was 'AVC + QoS' configuration.
I have created 'custom application' from Application Visibility. From my custom category I was able to see BLOCK_INDEED which I made.
I also created QoS policy-map and choose WLAN interface, but was uncertain which category should I choose cause there are three different custom category. (custom-category, custom1-category, custom2-category)
So I chose one of each, and applied to test WLAN. from test WLAN, policy also mapped.
It seems QoS is not implementing. Which step that I missed?
Appreciate your time.
07-31-2025 10:38 AM
There are two topics here which is not related
1- Url filter can I see how you config it.
2- QoS i will check it
MHM
07-31-2025 11:22 AM - edited 07-31-2025 11:26 AM
Hello!
URL filter was my first trial, and it is currently disabled to see QoS running.
Though, I'm sending URL filters. This rule was applied to my policy - Post-auth.
I also have tested few more URLs such as Teamviewer, Anydesk, but Anydesk blocking goes well unlike Teamviewer website accessing. It just let me in to Teamviewer.com or google search - Teamviewer and click the website.
Since URL filtering showed me different results for multiple times testing, so I would like to turn on both features - URL filteres, QoS policy map. Besides, it would be great if I could see the packet drop logs/stats..
Thank you very much.
07-31-2025 01:08 PM
Hello,
I realized that I have to choose 'Protocol' not 'Category' from QoS policy-map.
I was able to find BLOCK_INDEED from available protocol. However, still I am able to reach indeed.com even though I made QoS to drop.
07-31-2025 01:26 PM
Post-auth' meaning this url filter is filter url after client authc
But url filter is in real dns-based ACL
It work only if DNS answer to client request with A record if DNS answer with CNAME alias it not work.
So it can for non work url is that DNS send CNAME not A record.
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide