Allowing Specific Hosts to Access Blocked Applications Using Application Patrol

Zyxel_Judy
Zyxel_Judy Posts: 2,102  Zyxel Employee
Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
edited April 15 in Security Service

Overview

This guide explains how to configure Application Patrol on a Zyxel firewall (such as ATP 500) to block applications for all network users while allowing access for specific IP addresses.

Scenario

You want to restrict access to certain application categories (such as YouTube) for all users on your network except for specific devices (such as 192.168.2.34).

Configuration

Part 1: Allow a Specific Host to Access YouTube

  1. Create a Security Policy for the YouTube Allow Profile
    • Navigate to Configuration > Security Policy > Policy Control
    • Click Add, then Create New Object, and choose Address
01.png
  • Enter the Name, Address Type, IP Address, and click OK
02.png
  • Configure the Policy rule as required and click OK
03.png
  • Click Appy
04.png

2. Create an App Patrol Profile to Allow YouTube

  • Go to Configuration > Security Service > App Patrol and click Add
  • Enter a descriptive profile name
  • Search for "YouTube" in the Search Application(s) by Name field
  • In the Query Result, select the checkbox and click Add To My Application
05.png
  • In My Application, set Action to "forward" and Log to "log"
  • Click Save & Exit to save your changes
06.png

3/ Apply the profile to a traffic flow in a security policy.

  • When prompted after clicking Save & Exit, click Yes to open the "Apply Profile to a security policy" screen
07.png
  • Select Allow_YT_Host_P from the list.
  • Click OK to save your changes
09.png

Part 2: Block YouTube for All Other Hosts

  1. Create an App Patrol Profile to Block YouTube
    • Go to Configuration > Security Service > App Patrol and click Add
    • Enter a descriptive profile name
    • Search for "YouTube" in the Search Application(s) by Name field
    • In the Query Result, select the checkbox and click Add To My Application
11.png
  • In My Application, set Action to "reject" and Log to "log"
  • Click Save & Exit to save your changes
12.png

2. Apply the Block Profile to Your General Traffic Policy

  • When prompted after clicking Save & Exit, click Yes to open the "Apply Profile to a security policy" screen
13.png
  • Select LAN_Outgoing from the list
  • Click OK to save your changes
14.png

Verification:

  • The host 192.168.2.34 should now be able to access YouTube
15.png

  • Other hosts (such as 192.168.2.33) will be unable to access YouTube
16.png

You can view block logs at MONITOR > Log > View Log

17.png