This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

When is Transparent Webfilter applied? Understanding Webfilter in UTM

Hello everyone,

I have a Problem regarding Webfiltering in the UTM that absolutely eludes me.

Small Business, Small UTM with latest Firmware-Update.

We have 2 Networks. One which is allowed for Internet and one which isn't.

The Internet-Network has a Firewallrule to Internet allowed for HTTP/HTTPS
Additionaly it is in the allowed Networks for Web Filtering (Transparent). It only uses the Base Policy for Filtering.

The Offline-Network has no such Firewall rule and isn't part of the allowed networks. Should be blocked. Now we need to open the firewall a little for this network to install Windows Updates.
For this we have a Firewall rule to open traffice to WindowsUpdate-Servers with HTTP/HTTPS.

I had to troubleshoot this, because Windows Updates could not be downloaded.

After a along time, I made it work by adding the Offline Network to "Skip Transparent Mode Source Hosts/Nets" in the Misc - Filtering Options from Webfilter

Now i wonder. How is this possible??
When i tried the Policy Helpdesk, it said, that it was blocked due to not beeing in the Allowed Network list. So I assume, the offline-network should not be affected by webfiltering at all, but only by Firewallrules. How is it, that I need to put them in the webfilter sourc-ip-exceptions, for windows update to work.

I would greatly appreciate it, if someone might shed light to this.

Thanks in Advance

Olli



This thread was automatically locked due to age.
  • Ok. Now that i thought about it for a while. It seems to make sense. Fire Firewall rules says you can go to Windows Update Servers, then Webfilter ist applied and if you are not in the allowed list your are autmotically blocked. So probably would need to apply better exceptions for windows update? Do Exceptions take precedence over "allowed networks"?

    There are predefined on the UTM, which do not seem to work anymore. I also haven't found entries in the Webfilter for the Offline-Network.

  • Hallo Olli and welcome to the UTM Community!

    #2 in Rulz (last updated 2021-02-16) will help you answer your question.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA