This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issue with Url block

I am trying to block YouTube.com during specific time but it doesn't seem to be working. This was discussed previously here community.sophos.com/.../issue-with-rules



This thread was automatically locked due to age.
Parents Reply Children
  • Hi,

    please check if you have other rules that allow access other internet outside of your block times. You need to be enforcing access using allow and block rules in both web and application places.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I don't see anything that stands out. Also shouldn't the logs show how access is granted? 

  • You wil need to check both application and web logs. I found the application log not very useful because it only shows blocked applications.

    Once a connection is established from memory the XG does not block it, it will only block new connections, but I will be corrected on that if in error. I think I got the idea wrong last time and had to run a test for one of the sophos support people to prove the block does work at the correct time. I will run a test tomorrow and report back.

    Ian

    added extra info.

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi super_cm,

    I setup a the restriction profile and schedule and applied them to my application profile. I also changed the application policy to deny when applying the restricted time schedule.

    Results of testing

    1/. one VoIP service was locked after 40 seconds

    2/. the second VoIP service was dropped after 8 minutes.

    3/. the application logviewer showed only one attempt by one phone and multiple attempts by the other phone to restore a connection.

    4/. When the schedule and profile were deleted one phone took about 2 minutes to re-register, the other has not but that will e a configuration issue in VoIP ATA.

    5/. the deal between activation time and actual blocking time is very frustrating while trying to debug new rules.

    6/. I do not use web filtering on my VoIP services only application policy control.

    I Hope these results help with your issue?

    Ian

    corrected typing errors.

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I think this is my answer. It seems that the connection is still open and that's why it's allowing access.