Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Customized Notification for Blocked Websites not working

Hi,

I blocked few websites like youtube, facebook but when users are trying access the error message not appearing which i set in "User Notifications" instead of this the below message.

This site can’t be reached

www.youtube.com took too long to respond.

Try:

  • Checking the connection
  • Checking the proxy and the firewall
  • Running Windows Network Diagnostics
ERR_TIMED_OUT


This thread was automatically locked due to age.
Parents
  • If you disable the custom messages, do you get the regular block message?

    If it only affect custom messages - then the problem is somewhere in custom message.

    If it affects all messages - then the problem is in displaying anything.

     

    How did you configure the block? 

    If you are blocking in the firewall rule by not allowing traffic to those destinations, then what you see is expected.  The traffic never goes through the web proxy so the proxy cannot display a block message (custom or not).

    If you are blocking within the proxy, please explain your configuration.  There are a few ways to do it and it is useful to know which you did.

  • Hi,

    Enabling/disabling custom messages not effecting anything and same result showing in the browsers for all blocked websites.

    2nd- yeah i blocked the 3 website with follow these steps - Web Policy > Firewall Rule and attached that web policy.

    No proxy involved directly internet connection.

    How to achieve this to show some decent notifications to users?

     


    Thanks.

Reply
  • Hi,

    Enabling/disabling custom messages not effecting anything and same result showing in the browsers for all blocked websites.

    2nd- yeah i blocked the 3 website with follow these steps - Web Policy > Firewall Rule and attached that web policy.

    No proxy involved directly internet connection.

    How to achieve this to show some decent notifications to users?

     


    Thanks.

Children
  • But 1 thing is strange when i block whole "Social Networking" category so this message appear when i tried to open orkut.com

     

     

     

     

  • Hello ,

    The message shown above as the block message, was the user authenticated? We do have an option for unauthenticated users which is normally captive portal but you can set to choose User Notification. Location of the settings is configure > Authentication > Services >Captive portal.

    Also, could you please check your application filter logs for the issue with no block message shown?

    Regards,

    Aditya Patel
    Global Escalation Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • Thank you for the reply, i am not using any authentication and my scenario is like this - Web Policy > Web Categories blocking > Firewall Rules and assigning Web Policy.

    Still the user notification is not what i set in settings.

  • HI,

    It is strange, when users are trying to access ORKUT.COM so the correct notification message showing but once they open the facebook.com or youtube.com etc. so there is no message just an error. Same settings but different results for different URL's how? same user is accessing these websites form same PC.

    Both screen shots i am attaching for orkut.com and for other webs too.

     

     

     

     

  • The second pages are browser pages failing to reach something.

    The first one is actually XG sending Content.

     

    Seems like the client is getting a timeout.

    Can you verify, which route the client is taking to get to the internet? 

    __________________________________________________________________________________________________________________

  • Hi LuCar,

    I have 2 Firewall rules to allow internet.

    1st one for Management with full access and i added all the required Management  Mac addresses in this Rule and working fine.

    2nd one for other staff with many restrictions and i did not mention any addresses only applied Web Policy.

    But when the users are reaching to websites which are blocked so strange things are happening for example today i tried 20 social networking websites and 13 of them showed the correct block XG message but other 7 showed same timeout messages.

     

     

  • The question still remains, are those clients "actually" using the XG to reach those websites? 

    The browser tells us, there is a timeout trying to reach youtube. This could be, because the client is trying to use another route to the internet, which is not there. 

    __________________________________________________________________________________________________________________

  • Hi,

    I am the one who is testing/doing all these scenario so no other user here, i connected my 2 PC's directly with XG85 Lan and testing it.

  • Can you provide the Web logs of success and failure cases?

     

    If it is random websites but very consistent which ones, I'm wondering if it is something like failing for all IPv6.

  • Successful websites showing right block messages:

     

    www.orkut.com - www.dailymotiion.com - www.veem.com

     

    not showing websites.

     

    www.youtube.com - www.facebook.com - www.twitter.com