How to set USG to block an HTTPS website?
Since the Content filter can't filter HTTPS websites, how to set USG to block an HTTPS website?
SETUP/STEP BY STEP PROCEDURE:
There are two ways how the USG can block an HTTPS website:
Method 1. Please set up a firewall rule to block an HTTPS website:
Please add firewall rule with source:any; destination: https site's IP; Access: reject.
The USG will block all https access to the site.
Please refer to the picture below to set up the firewall rule on the USG:
Method 2. Please change the DNS server record to block the HTTPS website:
If IP addresses of websites are dynamic, you can also use the work-around of changing the DNS server address record to prevent access to the HTTPs websites.
Please add a DNS address record with FQDN, ex: *.facebook.com
Set its IP Address to: 0.0.0.0.
This can prevent computers from locating the websites via the DNS server. The method allows the USG to effectively block HTTPs websites.
Please refer to the picture below to set DNS server address record on the USG:
However, this work-around will fail if users locate the HTTPS website’s real IP by accessing an external DNS server.
Although this work-around may present some security risks, since the content filter can't filter HTTPS websites,Setting up a firewall rule and changing the DNS address record are the only ways to block HTTPs websites.
Setting up a firewall rule and changing the DNS address record are the only ways to block HTTPs websites.
As a result, the following page will be shown to users accessing HTTPS websites:
- 7.2K All Categories
- 6 Education Center
- 1.4K Nebula
- 39 Nebula Ideas
- 46 Nebula Status and Incidents
- 4.1K Security
- 206 Security Ideas
- 790 Switch
- 34 Switch Ideas
- 680 WirelessLAN
- 11 WLAN Ideas
- 4.7K Consumer Product
- 113 Service & License
- 234 News and Release
- 77 Stories
- 43 Security Advisories
- 546 FAQ
- 258 Nebula FAQ
- 124 Security FAQ
- 73 Switch FAQ
- 68 WirelessLAN FAQ
- 7 Consumer Product FAQ
- 30 Nebula Monthly Express
- 54 About Community
- 34 Security Highlight