This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Application control blocking websites

Hi,

one of our customer was trying to browse "https://apex.irclass.org:82 " but failed. I have allowed the fqdn and found nothing wrong logs in web filtering and application control logs. When i removed the application control, start getting the traffic.

Anyone can guide:

1. How to get the logs related to this issue.

2. How to allow "https://apex.irclass.org:82" in application control

Thanks in Advance



This thread was automatically locked due to age.
  • Application Control looks at things like destination ports, and port 82 is totally non-standard for HTTPS, so that's a plausible reason. (In fact, 81, 82, etc, seem to be used by some TORs, which would be suspicious.)

    When I try going to that link, entries show up in Log Viewer > Application Filter identifying it as a TOR Proxy, which makes sense. It gives a Policy ID of 4 and App Filter Policy ID is 8, though I'm not sure what to do to locate that and turn it off in Application Filtering.

    Worst-case, you could set up a firewall rule that has no App Filtering with destination of that particular domain, destination port 82. Make sure it's higher than the rules messing you up.

    • Thanks for the reply ! Through that process only im allowing the current traffic. Is it the standard way or there are anything else inside application filtering to  allow these non standard traffic? 

    • Hi Kripasindhu Ghosh

      Thank you for reaching out to the community, Are you using Sophos XG as a proxy server?

      If yes please go to PROTECT--->Web--->General Settings under Web proxy configuration and add port 82 allowed destination ports

       

      If a post solves your question please use the 'Verify Answer' button.

      "Sophos Partner: Networkkings Pvt Ltd".

      If a post solves your question please use the 'Verify Answer' button.