I have two FQDN hosts : Instagram (*.instagram.com) and Facebook (*.facebook.com). These two FQDN hosts are added in an FQDN host group named Social Media.
A rule in "Traffic to WAN" is configured for LAN to WAN that rejects this specific FQDN Host group. while testing this rule policy tester shows the packets being rejected as expected. When I test it in the client system, only the instagram.com is blocked. Can't seem to figure out why?
Hey New Temp ,
Thank you for reaching out to the community, may I ask the purpose of blocking this domains via FQDN, where as you can block this by creating a custom category.
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Yes but it is for educational purpose. Why a rule on top stating to reject packets for a specific domain name won't block the packets? I am unable to wrap my head around this. I'll take a look at that custom group you suggest but I need to know the reason for this behavior.
Hi New Temp ,
Reject action Drops traffic and sends an ICMP port unreachable message to the source for UDP and ICMP traffic. For TCP traffic, a TCP reset message is sent to the source.
Check Log Viewer for more information.
Regards
"Sophos Partner: Networkkings Pvt Ltd".
If a post solves your question please use the 'Verify Answer' button.