UTM Content Filter Not Blocking Forbidden Sites

Options
RunninWideOpen
RunninWideOpen Posts: 3
Friend Collector First Comment
edited April 2021 in Security
USG20W-VPN V4.60

Content filter is successfully blocking sites by category.   It will NOT filter Forbidden Sites.  I've tried adding multiple sites to the profile forbidden list, and the Common Forbidden List.   Neither are effective.


All Replies

  • chandan
    chandan Posts: 72  Ally Member
    First Anniversary 10 Comments Friend Collector
    Options
    Make sure to check on "Allow web traffic for trusted websites only".

    May be it is using different protocols to contact the web server other than the general one.

    In this case you can use application patrol to block that specific website choosing the application patrol profile as "Games".
  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    First Anniversary Friend Collector First Answer First Comment
    edited November 2020
    Options
    @RunninWideOpen
    Have you enabled Policy control? You can clean browser cache and check it again.
    From my lab, the website can be blocked.




    Result



  • RunninWideOpen
    Options
    Thanks for the responses.  Yes, policy control is enabled.  @Zyxel_Charlie I do notice that your screen shots are different than mine. Are you running FW 4.60?   On the router at my shop I had so much trouble after upgrading FW to 4.60 I had to rollback.  

    Anyway, on this problem I do see img.poki.com in the log showing up as forbidden, but it does not actually block it the webpage   I have emptied cache and tried again - I even downloaded a new browser and it still loaded the website.  

    As far as I can see, all my settings match your screen shots.
  • RunninWideOpen
    Options
    I just tried the forbidden sites at my shop running FW4.33 and it's working.    I believe the problem is with FW 4.60.
  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    First Anniversary Friend Collector First Answer First Comment
    edited November 2020
    Options
    @RunninWideOpen
    With 4.60, the website still can be blocked it on my lab.
    Result

    It seems it's browser saved the cache. Had you checked it before cleaned browser cache or used Incognito window, and renew PC's IP?

Security Highlight