Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Whitelist URL Blocking, FQDN Host.

Hello,

We are using one educational site which is hosted in "xxxxx-rearch-xxxx.x.assets.s3.amazonaws.com (scripts and image)" and " xxxxxxxxx.cloudfront.net(most of image) ".

For that we have allowed that site domain name along with this both this domain( xxxxx-rearch-xxxx.x.assets.s3.amazonaws.com, xxxxxxxxx.cloudfront.net) in FQDN host, and also in Web --> Exceptions URL list with Skip the selected checks or actions:- HTTPS decryption, Malware and content scanning, Sandstorm, Policy checks.

Created firewall rule that allow this FQDN host group without authentication along with Web policy "None" or "Allow all" and Application Control "None" or "Allow all" both ways.

 

 

AWS bucket change IP address very frequently as they doing because for security and for load balance of traffic.

What I am facing problem is when IP address is not updated in FQDN host list it will denied the traffic, so out of every 30 user 8 user's request gets denied.

Discussed with Sophos team and check everything related to DNS also. Change lots of DNS 127.0.0.1, 8.8.8.8, 8.8.4.4 and 1.1.1.1 for FQDN host update list.

There are 24 or more IP address ranges of AWS S3 bucket and Cloudfron.net,  if we allowed all ranges, lots of other site will be accessible without authentication, which is Great pain in Educational environment.

 

S3 Bucket and Cloudfront.net

https://ip-ranges.amazonaws.com/ip-ranges.json

 

Any solution on this ?



This thread was automatically locked due to age.
Parents
  • Hi,

    so what you are really after is a means of forcing the XG DNS to do regular FQDN checks eg every 10 seconds or so?

    Are you able to provide a time between FQDN IP address changes eg every 30 minute, 15 seconds etc?

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi,

    so what you are really after is a means of forcing the XG DNS to do regular FQDN checks eg every 10 seconds or so?

    Are you able to provide a time between FQDN IP address changes eg every 30 minute, 15 seconds etc?

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Children