This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Block access from a device to some domains, leaving everything else untouched?

Hi... 

I've just started using UTM (v 9.401-11) and love it so far - however I've run into one issue which I'm trying to understand.

I have a media streaming device (an Amazon Fire TV) which I want to block from accessing certain domains, to prevent it from auto-updating. What I want to do is only to block http and https access to these domains, and leave all other traffic from the device untouched. I was hoping to use the web filter for this, and it is successful in blocking access to the domains - but as soon as I enable the filter, media streaming to the device fails - Netflix is what I'm testing with specifically. What actually happens is with the filter enabled, the Netflix app launches but then almost immediately crashes back to the homepage.

I've configured a filter profile for the device as follows:

  • Just the device set as allowed network
  • transparent mode
  • HTTPS: URL filtering only (Makes no difference if I select "Do not proxy HTTPS traffic in transparent mode")

The default content filter is set to allow everything, no antivirus scanning. Under 'filtering options / Misc' I have "Bypass content scanning for streaming content" selected.

I've also tried adding the exceptions described here: https://community.sophos.com/products/xg-firewall/f/129/t/74689

In the web filtering live log, every entry appears to be a pass - I can't see anything being blocked or denied when trying to access Netflix.

Am I doing anything obviously wrong, or - preferably - is there a simpler way to achieve what I want to do, i.e. to simply block access to a few domains and leave everything else untouched?

Hopefully this make sense :)



This thread was automatically locked due to age.
Parents
  • Wouldn't it be better to create a new profile and new policy for the specific device, and explicitly just block these domains? (Web Protection -> Web Filter Profiles )? 

    Set the "allowed networks" to the specific device, and create a profile that as the domains you want blocked in the "block website" list.

Reply
  • Wouldn't it be better to create a new profile and new policy for the specific device, and explicitly just block these domains? (Web Protection -> Web Filter Profiles )? 

    Set the "allowed networks" to the specific device, and create a profile that as the domains you want blocked in the "block website" list.

Children
No Data