If you think the content filter is not working as expected
Symptom:
If you think the content filter has not worked the webpage as expected.
Checking:
1) Please block QUIC Ports.
QUIC uses UDP port 80 and port 443. The complete TLS client Hello, including any TLS Server Name Indication (SNI) present, is sent in one or more CRYPTO frames across one or more QUIC Initial packets.
2) If there are multiple categories, as long as it matches one of them, it will be blocked.
For example, if block Streaming Media or Media Sharing. Youtube will be blocked.
Route>configure terminal
Router(config)# content-filter url-server test
Router(URL)#
result_all: Streaming Media, Media Sharing
HTTPS Domain Filter result_all: Streaming Media, Media Sharing
Botnet result_all: Not Found
The query takes: 1.000000 seconds
3) For HTTPS traffic we will check the content of SNI. Please check if there are managed URL in packets
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 147 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight