Hi , I am on Sophos XG 18.5.
URL to block: www.google.com/.../ads.js
I have added a custom blocking category with keyword filters like below
www.google.com/adsense/search/ads.js
search/ads.js
but this does not block this site.
When I do a policy test, it shows the correct policy, when when I test this URL it passed through it. I have tried decryption as well, does not work,
either block the entire domain i.e google.com or does not block at all
it
Please advice
So if you use the Tester on the policy, it shows the policy does what you want.
So if you use the Tester on the traffic, it shows that it is not using that policy.?
It says that will use Firewall Rule 5. It says that rule will use DPI mode and not Proxy mode. It says that the traffic will not be decrypted (in DPI mode this means that the SSL/TLS rules do not decrypt the traffic).
If you are not decrypting the traffic then only the domain name is used for categorization/url groups. The path is not visible/useable as it is encrypted.
URLs are never encrypted; only data in the HTTP headers and body and packets are encrypted, even in given article it does not talk about if we need to decrypt
I had PF Sense earlier and that can be done easily without decrypting, possibly I am missing something, looks like I have allowed google somewhere, .
https://support.sophos.com/support/s/article/KB-000036901?language=en_US