Content filter on ATP800 not working

Pedroj
Pedroj Posts: 53  Ally Member
Fifth Anniversary 10 Comments

Hello, the content filter seems to not be working correctly.
By blocking categories such as social networks or pornography, you can access it without problem.
I have also activated the DNS content filter and I can also access it even if it is in blocked categories.
Any idea what is happening?

«1

All Replies

  • PeterUK
    PeterUK Posts: 3,149  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    edited April 22

    Set “action when category server is unavailable” to block

    move rule to top of the list

    Might a VPN or proxy be in use by the client?

  • YanShadowGT
    YanShadowGT Posts: 11  Freshman Member
    Fourth Anniversary Friend Collector First Comment

    Hello Zyxel, what is happening, I have the same problem as of Wednesday, April 17, I thought it was some bad configuration of mine, but in the same way my USG1100 fails, the content filter does not work. I hope they resolve it soon. This problem only happens with Edge and Chrome, Firefox still respects the Content Filter

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 860  Zyxel Employee
    100 Answers Second Anniversary 500 Comments Zyxel Certified Sales Associate

    Hi @Pedroj , @YanShadowGT ,

    Greeting Forum, Could you share your config file by Private message ?

    Thank you

  • WJS
    WJS Posts: 155  Master Member
    100 Comments Second Anniversary Friend Collector 5 Answers

    Try to disable if you are using Chrome

    chrome://flags/#enable-tls13-kyber

  • Pedroj
    Pedroj Posts: 53  Ally Member
    Fifth Anniversary 10 Comments

    Hello, I don't understand very well, but this morning everything is working without changing settings?
    What can be the motive?

  • YanShadowGT
    YanShadowGT Posts: 11  Freshman Member
    Fourth Anniversary Friend Collector First Comment

    Hi @WJS

    Thank you for your support, you have solved the problem with the content filter, I hope Zyxel solves this incompatibility with this TLS 1.3 encryption. Since Google says that this option will be temporary and will not allow it to be disabled in future versions.Thank you again!!!

  • electsystech
    electsystech Posts: 37  Freshman Member
    Fifth Anniversary 10 Comments Friend Collector

    We found the same problem on the Zyxel USG310 and USG Flex 50 routers. I didn't test any other models yet, these are the ones that we had reports that the content filter isn't working on. I'm guessing we have over a 100 routers with content filter subscription on them. So we need an update to fix this as trying to disable TLS 1.3 on each computer at every company is not a practical solution.

  • PeterUK
    PeterUK Posts: 3,149  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    edited April 24

    Even if Zyxel fix the problem it may only be for current models and not EOL ones

    The DNS Content filter should work if you don't use dns over HTTPS

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 860  Zyxel Employee
    100 Answers Second Anniversary 500 Comments Zyxel Certified Sales Associate

    Hi @electsystech

    We're aware of the issue from TLS1.3 Kyber,

    We're working on it.

    Thank you

  • electsystech
    electsystech Posts: 37  Freshman Member
    Fifth Anniversary 10 Comments Friend Collector
    edited April 25

    We sent a request into Zyxel to have HQ look into this. The content filter policies and DNS content are no longer working. This is a significant problem and hopefully a router firmware patch can be released quickly.

Security Highlight