USG Flex 200 blocking website?
Freshman Member
Hello, can a USG Flex200 suddenly block a website resulting in browsertext: "Access denied" ? There is no other text in the browser. I can´t find anyting in the log. There is no problem accessing the site from other connections. It´s also possible to access the site site directly in the fiberbox (on other public IP via DHCP).
All Replies
-
Hi @Hakandenende,
Yes, a USG Flex 200 can indeed block a website, even if it appears to happen "suddenly," and display an "Access denied" message in the browser. There are several reasons why this might occur, and the lack of a clear log entry can make troubleshooting challenging.
Here are some steps to investigate this issue:
Review Security Policies and Services:
- Content Filtering: Check your Content Filtering profiles to see if the website's category or specific URL has been inadvertently blocked. Note that Content Filtering does not block traffic through DNS but checks the SNI in the TCP Client Hello. For HTTPS traffic, ensure "Enable HTTPS Domain Filter for HTTPS traffic" is checked and consider enabling SSL Inspection for more comprehensive filtering.
- DNS Content Filter: If you are using DNS Content Filter, verify its configuration. It can enhance blocking effectiveness, especially with Encrypted SNI (ESNI).
- Threat Detection/Prevention: While you haven't found specific logs, ensure that Intrusion Detection and Prevention (IDP) or other security features are not mistakenly flagging legitimate traffic to the website.
- Firewall Rules: Review your firewall rules for any explicit deny rules that might be affecting access to the specific website or its IP address.
- Geo-IP Blocking: Check if Geo-IP blocking is enabled and if the website's server IP address is located in a blocked region.
Firmware Version: Ensure your USG Flex 200 is running the latest firmware version. Browser updates with new protocols like TLS 1.3 Kyber can sometimes interfere with web content filtering if the firmware is outdated.
DNS Resolution:
- The USG Flex performs DNS lookups. There could be an issue with how the USG Flex is resolving the domain name of the blocked website.
- If disabling Wi-Fi on a mobile device and accessing the site works, it points to an issue within the USG Flex network for that specific domain.
To help us further diagnose the problem, please provide the following information:
- USG Flex 200 Firmware Version: This can be found in the device's web interface.
Screenshots of relevant configurations:
- Content Filtering profiles.
- Firewall rules that might be applicable.
- DNS settings on the USG Flex.
The specific website URL that is being blocked.
- Network Topology Map: A simple diagram showing how your USG Flex 200 is connected to your network and the internet.
- Troubleshooting Steps Taken: Any specific configurations you've already tried.
This AI response aims to provide initial troubleshooting steps and identify information needed for further diagnosis. Feel free to share additional details based on the suggestions above — this will help community members offer more targeted assistance.
If you have feedback or idea about this AI assistant, share them in Community Feedback.0 -
What is the category of this log? Could you share the full log screenshot so we can better check this issue?
Zyxel Melen0 -
@Hakandenende try to check your url here :
0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 219 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.5K Security
- 588 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 477 News and Release
- 91 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight
Zyxel Community Virtual Assistant
Ally Member