Customers might be unable to connect with us via the Sophos Malaysia Support Hotline number. Our teams are actively working on a fix. In the interim, we request customers to use the backup hotline number - +65 3157 5922 (Singapore) or raise a support request at https://support.sophos.com/.

Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall rule Facebook / Web URL / App-Filter

Hello,

for example, I would like to create a firewall rule that is used for various clients when using Facebook.

I created various IP hosts, web URLs and also an application filter for Facebook. But it looks like the rule, visible on the basis of the traffic, is not attracted to the rule. Is that basically possible or what would be a procedure.

Greeting



This thread was automatically locked due to age.
Parents
  • Hi,

    you need to be using policies which are applied to firewall rules. Are you trying to stop facebook access, also there are default exceptions in there web exceptions for facebook.

    the enforcement of policies is via firewall rule using web, application and IPS settings in the Proxy or DPI.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi,

    if I have understood that correctly, I should use the web filter in the firewall rule and also the application in the firewall rule.

    Is that right ???.

  • The questions have been answered, but you do not seem to want to understand the answers.

    the rules are processed top to bottom. Criteria can included network or device IP address, is the URL in the blocked list, is the application allowed, is the port valid. All these things show in the logviewer when you review the filtered output.

    ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I am fully aware of and understood the principle that every rule is processed from top to bottom and that the rule is then executed on the basis of the criteria.

    Problem, which unfortunately also arises, that I use a switch behind the XG, also means that I cannot see everything in the log. But I'm only talking about rules that are set up in the direction of WAN.

    Again the question, what is one of the criteria that a rule is executed.

    Ask again, if the web rule usually applies, but is usually valid for every client, is it then carried out?

    It is different if a web filter and an application rule are usually stored and the rule applies to all clients,
    the WebFilter is valid, but the application is not, is this rule executed?

    Are all mechanisms usually summarized as a logical AND or an OR link that a rule is executed.

    That is a very crucial thing.

  • Firewalls are always applied based on Source IP, Destination IP and Service. 

    You can replace Source IP by Username in context of a user based Firewall rule. 

    There are no other criteria. If the firewall rule hits, it will apply the filters, attached to the rule (Web, app, ips etc.). 

    __________________________________________________________________________________________________________________

  • ok, thank you, that fits, I can start something with that.

    Thanks

  • I have to ask again

    there is only one criterion, either with the IP / subnets or the users that a rule is applied to.

    greeting

  • Its first match. 

    __________________________________________________________________________________________________________________

  • OK,
    I don't know how to solve the problem. All my rules are not working properly.

  • Use the policy tester to check, which policy is applied. Then check the affected policy, if all the wanted filters are applied. 

    __________________________________________________________________________________________________________________

  • I'm not even sure if it's the WebFilter or the firewall rules.

  • You need to understand, firewall rules are the way to apply filters. If there is no firewall rule, it will not apply anything. IPS, Web, App control is a filter, which will apply after a firewall rule attached this to the traffic.

    __________________________________________________________________________________________________________________

Reply
  • You need to understand, firewall rules are the way to apply filters. If there is no firewall rule, it will not apply anything. IPS, Web, App control is a filter, which will apply after a firewall rule attached this to the traffic.

    __________________________________________________________________________________________________________________

Children