This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall rule Facebook / Web URL / App-Filter

Hello,

for example, I would like to create a firewall rule that is used for various clients when using Facebook.

I created various IP hosts, web URLs and also an application filter for Facebook. But it looks like the rule, visible on the basis of the traffic, is not attracted to the rule. Is that basically possible or what would be a procedure.

Greeting



This thread was automatically locked due to age.
Parents Reply Children
  • Check your Firewall rule for the device, there is also a option to decrypt the traffic. 

    __________________________________________________________________________________________________________________

  • What should I check there?

    I don't understand what to check there. ???

    I also don't see in the LOG where the problem is, I see the WebFilter appear and are also allowed, but nothing works anyway.

    Now I have to go back to ANY ANY, so it can't be that slow.

    I look carefully at the one client filtered in the log. The firewall rule and the web filter are all GREEN. No red one among them.

    I don't understand where the problem is, for days and hours nothing works, except ANY ANY.

    I'm slowly losing my nerve with this nonsense. I've already learned a lot about it, but that can't really work properly.

  • Thats a rule to select some services.

    it doesnt work

  • You need to understand, if you attach a filter control rule, it can mess up with the traffic. Some devices are not build to work with this. 

    Switch everything off in Web filtering and remove the web policy. Try again if it works or not. 

    __________________________________________________________________________________________________________________

  • Since I didn't understand, sorry, please explain again in more detail.

    Thanks...

  • Change web policy to allow all.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi,

    now I do not understand anything anymore.

    How should I now apply the web policy for various clients and / or users?

    Why then should the WebPolicy rule be applied in the firewall rules at all?

    So that somehow misses my understanding.

    greeting

  • You are trying to test an any any rule so you don't need the default web policy. You normally use an any any rule with minimal restrictions to see what sites and ports an application /PC go to so you can restrict access and improve security of your network in your then specific rules for that device.

    The web policy allows you to fine tune a rule for each client group/users on a rule be rule basis.

    I have a number of web and application policies that apply to my apple devices, my security cameras, my VoIP services and other IoT devices. Some have very specific policies and others have limited policies.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • ok, i already got that with the web policy.


    But I thought you would have to include the WebPolicy in a firewall rule and apply it.

    Or do I create a firewall rule with Any / Any without users or clients and then only apply the WebPolicy.

    The Friewall rules are then only to restrict the clients between the subnets etc. and / or services?

    I don't understand when one now

    - where an application rule is used

    - where a web policy is used

  • Web and application policies are used when you want restrict access to specific functions. You do not have to apply any web or application policies. If you want to use the proxy you would choose allow all in the web policy so you can see the classification in your reports if you so desire. I have created my own places to use with blocking certain security avoiding application but because some of my devices use tunnels I have had to fine tune the generic block all tunnels policy.

    Policies are all about managing user access and providing a secure managed network. There are a number of default policies which are provided so you have something to use as a reference when building your own, they are very generic.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.