This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Facebbok app not blocked on Apple device

Hi everybody,

my device is a Sophost UTM9 ASG220.

I configured Application Control to block all Social Networking applications. Unfortunately Facebook App is not correctly blocked when accessed by Apple devices (iPhone-iPad).

This is the log I see when Facebook app is accessed:

/var/log/http.log:2017:02:09-17:01:40 gbgnudiwall httpproxy[5657]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="10.0.0.117" dstip="195.10.50.182" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_HttProGbwebfilte (GBwebFilter)" filteraction="REF_HttCffGbfilterac (GB_filterAction)" size="0" request="0xdf0e7600" url="gspe19.ls.apple.com/tile.vf referer="" error="" authtime="0" dnstime="0" cattime="172" avscantime="0" fullreqtime="16905" device="0" auth="0" ua="T84QZS65DQ.com.facebook.Facebook" exceptions="av,sandbox,fileextension" category="105" reputation="trusted" categoryname="Business"

I see that the URL is categorized as Business and so it passes the web filter named GBwebFilter I configured.

 

Did anyone experience this issue? What can I do to solve it?

Thank you in advance,

Federico



This thread was automatically locked due to age.
Parents
  • Hi, Federico, and welcome to the UTM Community!

    Since the log line you showed us does not relate to Facebook, I'll guess that the Facebook access is not going through Web Filtering, but via a firewall rule.  Facebook uses HTTPS, so, if you're in Transparent mode, you must, select  to allow the Proxy to see the Facebook requests.  That means, at the least, selecting 'URL filtering only' and not selecting 'Do not proxy HTTPS traffic in transparent mode'.  Did that resolve your issue?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi, Federico, and welcome to the UTM Community!

    Since the log line you showed us does not relate to Facebook, I'll guess that the Facebook access is not going through Web Filtering, but via a firewall rule.  Facebook uses HTTPS, so, if you're in Transparent mode, you must, select  to allow the Proxy to see the Facebook requests.  That means, at the least, selecting 'URL filtering only' and not selecting 'Do not proxy HTTPS traffic in transparent mode'.  Did that resolve your issue?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data