This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Filter Bypass Issue with URL Groups

Hello.

I've come across a minor issue with the Web Filter where a user may still be able to load a webpage, even though it is 'blocked.'

Running the latest version of XG firewall (18.0.4 MR-4).

To replicate:

1. Create a URL group and add a domain, for example: example.com

2. Create a User Activity with the URL group added.

3. Create a web filter Policy, denying the above created User Activity.

4. Apply the web filter Policy to a firewall rule.

On a PC impacted by the firewall rule, load the URL with a period (.) at the end of the URL. For example: http://example.com.

Without the period at the end of the URL, the webpage is blocked (as expected). With the period, it loads in full.

One more thing, the PC points to the XG for DNS.

Is anyone else able to replicate this issue?



This thread was automatically locked due to age.
Parents Reply
  • It is technically a valid domain name - eg it matches the internet specification.  However they are almost never used.  Most web servers will redirect you to what they consider the "normal" FQDN is.  Several web browsers will automatically change the domain name to the one without the period.  Therefore in normal browsing the chance that this happens/matters is very low.  Yes a malware author could use this to bypass some checks, however it is not a common technique.


    The system that looks up categories based on the domain name incorrectly considers them to be invalid.

    The URL Group is used in several different areas.  Some areas may not do the matching correctly.

Children