[NEBULA] Can NSG100 block user access to certain website?
Comments
-
Hi JINHANG!
Yes, you can block the access for defined IP addresses. Similar as in the other thread, once you have identified the IP address or network that you want to block, you can create an application profile for the Facebook category with action Drop/Reject and create the outbound rule with the specific source IP address. In case you have more outbound rules, be sure to place this outbound rule on top of others that allow traffic from any source.0 -
can i block the website by domain name ? cause nowadays a website can end up with many IP addresses.0
-
@newtype
For security reasons, blocking using domain name is not available. If someone could change your DNS it would suddenly open gaping holes in your firewall to stuff you didn't want accessible, and since a lot of people don't treat DNS servers as a very 'securable' system, it is a low-hanging fruit.
To address the many IP addresses issue in a more secure way, the NSG uses application patrol which also simplify settings by updating signatures every day.0 -
@Nebula_Bayardo
I don't quite get your saying about security reasons ..
in your USG today, you have walled garden, so it's just turned that around to become black list. then you can be more friendly to achieve "block user to certain website". please consider it ~0 -
Hi @newtype the walled garden limit the access to those web sites listed, prior to an authentication process (Captive portal), but does not block access by user as specified by JINHANG. It would work when you want to limit the access for certain users connected to a specific interface, but once the users have logged in, the walled garden doesn't take effect anymore.
BTW, here's a sneak peek , our NSG100 will be able to configure walled garden in Phase II launching in May this year!0 -
hey @newtype I've read your comment again and got your point! Yes, it's sounds like a good idea to reverse the walled garden function to become a "black list".
Would you mind to re-post this fantastic suggestion to "Ideas" category where other users can support you by giving your post a Like ? I can do it for you if you are agree!1 -
Sounds cool! Please go ahead ~0
-
@newtype I have posted your idea, go and give it a Like!
Thanks for your support to make Nebula even better!
1
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 148 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight