How to block YouTube access by schedule
USG Flex/ATP with Scheduled YouTube Access Settings Example
Note: All network IP addresses and subnet masks are used as examples in this article. Please replace them with your actual network IP addresses and subnet masks. This example was tested using USG FLEX 200 (Firmware Version: ZLD 5.31).
Set Up the Schedule on the USG Flex/ATP
In the USG Flex/ATP, go to CONFIGURATION > Object > Schedule > Recurring > Add Schedule Recurring Rule. Configure a Name for you to identify the Schedule Recurring Rule. Specify the Day Time hour and minute when the schedule begins and ends each day. In the Weekly schedule, select each day of the week that the recurring schedule is effective.
CONFIGURATION > Object > Schedule > Recurring
In the USG Flex/ATP, go to CONFIGURATION > Security Service > App Patrol > Profile Management. To add an App Patrol profile, configure the profile name and select “Search Application(s) By Name”. Then enter the keyword “youtube” to search the key-related results.
Select all YouTube-related apps and press Add To My Application.
Modify Action from “forward” to “drop” and press Save & Exit.
Set Up the Security Policy on the USG Flex/ATP
In
the USG Flex/ATP, go to CONFIGURATION
> Object > Service to add a UDP 443 service object.
Go to CONFIGURATION > Security Policy > Policy Control to configure a Name for you to identify the Security Policy profile. For From and To policies, select the direction of travel of packets to which the policy applies. Select the service QUIC_UDP443 and select the Schedule that defines when the policy would be applied. In this example, select “Youtube_Blocked_Time”.
Add another security policy to block YouTube by schedule. To configure a
Name and the From, To traffic
direction. Select the Schedule that
defines when the policy would be applied.. Finally, to scroll down the Profile, check Application Patrol and select a profile from the list box. In this
example, Schedule:
Youtube_Block_Time; Application Patrol:
Youtube.
Then go back to the security policy page and move the security priority of block UDP 443 is higher than block YouTube by schedule.
Test the Result
Type the URL http://www.youtube.com/ or https://www.youtube.com/ onto the browser and cannot browse YouTube, as below:
Open the YouTube APP on the phone and cannot access to YouTube, as below:
Go
to Monitor > Log, you will see
[alert] log of blocked messages.
If
you are not able to configure any Application Patrol policies or it’s not
working, there are two possible reasons:
- You have not subscribed for the Application Patrol service.
- You have subscribed for the Application Patrol service but the license is expired.
You can click the link from the CONFIGURATION > Licensing > Registration screen of your Zyxel device’s Web GUI (http://portal.myzyxel.com/) to register license service or extend your Application Patrol license on Zyxel Marketplace (https://marketplace.zyxel.com/).
Finally, go to the CONFIGURATION > Licensing > Registration > Service and click the Service License Refresh button to update the status and the Application Patrol service shall be working.
See how you've made an impact in Zyxel Community this year!
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 146 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight