Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XGS googleadservices.com

Hallo Zusammen,

googleadservices.com wird scheintbar out-of-the-box von einer XGS als Advertisements erkannt:

Die o.g. Meldung ist erst lesbar wenn man das XGS CA Zertifikat importiert hat.

Eine Web>Exception hilft nicht:

microapp-discovery sind aus:

Der Policy Test zeigt Blocked:

Kein Web-Proxy:

Was ist zu tun? Vielen DANK !!



This thread was automatically locked due to age.
Parents
  • Hello there,

    Good day and thanks for reaching out to Sophos Community 

    I see on your screenshot you are using the "Default Policy" in Web policy section

    If you have not made any changes, the Default Policy blocks the User Activity "Suspicious".  If you then go to the User Activity tab you see that Suspicious includes the category Advertisements.

     

    So, anything that uses a firewall that has a web filter policy of Default Policy will have Advertisements blocked.  The way the XG blocks advertisements is with a block page served using its own CA.

    If you do not want to block advertisements, the easiest thing is to add a rule to allow Advertising above the rule to block Suspicious.  Alternatively you can change the block Suspicious to a your own list of categories or even change the definition of suspicious.

     You may also want to try clicking on the Log Viewer (top right corner) and then switch to Policy Test.  That can be used to determine exactly why you are being blocked.

    Hope this helps. Many thanks for your time and patience and thank you for choosing Sophos

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

Reply
  • Hello there,

    Good day and thanks for reaching out to Sophos Community 

    I see on your screenshot you are using the "Default Policy" in Web policy section

    If you have not made any changes, the Default Policy blocks the User Activity "Suspicious".  If you then go to the User Activity tab you see that Suspicious includes the category Advertisements.

     

    So, anything that uses a firewall that has a web filter policy of Default Policy will have Advertisements blocked.  The way the XG blocks advertisements is with a block page served using its own CA.

    If you do not want to block advertisements, the easiest thing is to add a rule to allow Advertising above the rule to block Suspicious.  Alternatively you can change the block Suspicious to a your own list of categories or even change the definition of suspicious.

     You may also want to try clicking on the Log Viewer (top right corner) and then switch to Policy Test.  That can be used to determine exactly why you are being blocked.

    Hope this helps. Many thanks for your time and patience and thank you for choosing Sophos

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

Children
No Data