Dynamic App Control not working as expected

Hi,

in v17 Beta 2 I tried to do the following:

- All HTTP traffic should be filtered via Web Protection

- One Application (e.g. Brave Browser) should have direct access without proxy

 

Therefor I configured the following:

- Rule 1: Allow HTTP/HTTPS from LAN to WAN for Brave Browser (discovered by synchronized app control)

- Rule 2: Allow HTTP/HTTPS from LAN to WAN with content scanning "Scan HTTP" and Web Policy to block certain URLs

 

What I see:

- All HTTP traffic matches the first rule (Brave Browser, Firefox Browser, Chrome Browser)

 

Cheers

auda

- But in the Synchronized Application Control Pane the "Occurances"-Counter for the different Browsers rise as expected

 

Is this a bug or a wrong configuration or a misunderstanding of the Synchronized Application Control feature?

Parents
  • Hi,

    please post a copy of your rules so we can review them and maybe help you.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi,

     

    I think these are the relevant parts.

     

    Cheers,

    auda

     

    Policy:

    Rule ID 4:

    Rule ID 5:

    Application "Brave Browser":

    Application Filter "Allow Brave":

  • I forgot the logs. All HTTP/HTTPS traffic matches Rule ID 4.

     

    Cheers,

    auda

  • Hi,

    It is not clear to me what brave is? Also you are allowing http and https out through the brave rule?

    I think you will need a web rule as well as the application rule.

     

    Ian

    Update:- investigated 'Brave Browser' and you will need to add TOR and block all other VPNs. FF already uses TOR. You might find that eventually TOR gets blocked by your ISP as a security risk or maybe even the various countries' security teams.

    So in summary, I think you will need some more sophisticated rules in application, web and firewall to achieve your aim. Further by using Brave you are advertising the fact that you might be a security risk. My personal opinion only.

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Brave is a Web Browser like Firefox, Chrome or Internet Explorer. It is just an example for any application that is using HTTP or HTTPS to communicate with some servers in the Internet. In Germany there is a tax program (Elster) that is famous for not working correctly with a proxy. The same applies to many of these cloud-enabled applications (Office 365, Autodesk 360, et al).

    I just want to make sure, that all "normal surfing" traffic is protected via the proxy, but some applications (that are using also HTTP/HTTPS) have direct access to the internet.

     

    Cheers,

    auda

Reply
  • Brave is a Web Browser like Firefox, Chrome or Internet Explorer. It is just an example for any application that is using HTTP or HTTPS to communicate with some servers in the Internet. In Germany there is a tax program (Elster) that is famous for not working correctly with a proxy. The same applies to many of these cloud-enabled applications (Office 365, Autodesk 360, et al).

    I just want to make sure, that all "normal surfing" traffic is protected via the proxy, but some applications (that are using also HTTP/HTTPS) have direct access to the internet.

     

    Cheers,

    auda

Children