This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Web Filtering Appliance

Hi all,

I have recently implemented a Sophos Virtual Web Filter appliance and I have  few questions:

In the reporting, 'Top Users By Browse Time' is showing 18+hours browsing per day for some users, is there any way to make this more accurate as this is obviously not correct?

Report Exemptions allow me to exempt a category or an individual url from being included in a report, is there anyway to exempt ALL url’’’’s ending with the same domain e.g all of our servers are xxxxxxx.DOMAIN.LOCAL?

Also in report Exemptions I need to exclude the whole of our internal IP range, does anyone know how you would do this as it only seems to let me add 1 x IP address at a time.

I did ask these questions to Sophos Support but wanted to see if anyone here had any suggestions on any of these.

Thanks in advance.

:37351


This thread was automatically locked due to age.
Parents
  • Hi. Welcome to Sophostalk!

    It could be that the user has left their system on overnight and there is some automated software which repeatedly accesses the web.  Unfortunately there is no way for the appliance to distinguish this from 'normal' traffic.  

    If it is caused by some specific traffic you can exclude that from reports to improve accuracy.

    By the way, if you're interested in how the report is calculated...

    /search?q= 13773

    --------------------

    For the exemptions, domain.local will exclude sub-domains / hosts.  

    However, you can't exempt an IP range.  You could disable the logging of internal traffic completely by following these steps:

    • Go to 'Configuration | Group Policy | Local Site List'.   Add your IP range as CIDR:  Eg. 192.168.0.0/16
    • Create a tag for the entry and Save.
    • Go to 'Configuration | Group Policy | Additional Policies'.  Add a new policy
    • All users must be a member of the policy.  Add a group containing all users
    • Go to the 'Tags' section and add the tag you created earlier.  Set it to 'Allow'
    • *EDIT* On the 'Name and schedule' tab select 'Do not log traffic for this policy'
    • Name and save the policy

    Alternatively, if you don't need internal traffic to go through the appliance at all, you can usually stop that happening.  For example, by using proxy exceptions in the web browser.

    Hope this is of some help.

    - Tom.

    :37369
Reply
  • Hi. Welcome to Sophostalk!

    It could be that the user has left their system on overnight and there is some automated software which repeatedly accesses the web.  Unfortunately there is no way for the appliance to distinguish this from 'normal' traffic.  

    If it is caused by some specific traffic you can exclude that from reports to improve accuracy.

    By the way, if you're interested in how the report is calculated...

    /search?q= 13773

    --------------------

    For the exemptions, domain.local will exclude sub-domains / hosts.  

    However, you can't exempt an IP range.  You could disable the logging of internal traffic completely by following these steps:

    • Go to 'Configuration | Group Policy | Local Site List'.   Add your IP range as CIDR:  Eg. 192.168.0.0/16
    • Create a tag for the entry and Save.
    • Go to 'Configuration | Group Policy | Additional Policies'.  Add a new policy
    • All users must be a member of the policy.  Add a group containing all users
    • Go to the 'Tags' section and add the tag you created earlier.  Set it to 'Allow'
    • *EDIT* On the 'Name and schedule' tab select 'Do not log traffic for this policy'
    • Name and save the policy

    Alternatively, if you don't need internal traffic to go through the appliance at all, you can usually stop that happening.  For example, by using proxy exceptions in the web browser.

    Hope this is of some help.

    - Tom.

    :37369
Children
No Data