This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webfiltering is allowing blocked websites to be accessed.

I am having this issue again where the web filter is being bypassed and allowing blocked websites to load. I am simply trying to add a website to the blocked list. As an example, I am trying to block "Foxnews.com" from loading.

 

Simple enough, right? No.

 

Web filtering: Enabled

In the Web Filter Profiles, under Default content filter block action, in the Websites category I have http://www.foxnews.com and https://www.foxnews.com blocked (include subdomains), yet they are allowed to load.

In the Web Filtering section, I have my Internal network in allowed networks, set to transparent mode. Default authentication: none. HTTPS URL filtering only. The issue isn't HTTPS certificates (decrypt and scan) because even non-HTTPS websites are being loaded.

 

I have tried both Firefox and Chrome browsers. both allow blocked sites to load. The add-on HTTPS Everywhere has been removed.

In Web Filter Profiles, nothing is listed in the window, but Default Web Filter Profile is enabled.

In the policy helpdesk, Foxnews is allowed URL category General News. When viewing the Webfilter live log, nothing appears when I go to any of the blocked websites I have entered.

Sophos UTM 9.504-1



This thread was automatically locked due to age.
  • After more tinkering around with the settings, I noticed that the Base Policy filter action was set to Allow instead of Default Content filter block action. It seems the problem is fix.

     

    But it seems Sophos is picky about how you specify the address of a domain.

    Does a user type in

    Foxnews.com

    Foxnews.com/

    www.foxnews.com

    www.foxnews.com/

    http://www.foxnews.com

    And when using the "/" after a website name is is necessary to also check "include sub domains"?

  • Alan, you're confusing 'Match URLs based on: Domain' with 'Match URLs based on: Regular Expression'.  With the former, you use foxnews.com and select 'Include subdomains'.  With the latter, you would use ^https?://[A-Za-z0-9.-]*foxnews\.com/

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA