security policy does not block traffic
I created the blocking rules based on the content filter categories, but they are not being blocked. For example, online radios (to reduce bandwidth usage) are not being blocked, some categories do accept the block, but most just pass through the policy.
All Replies
-
You likely have to move the rule to the top as any rule above could be allowing the traffic before it gets to the content filter rule.
0 -
Hi @DGALDINO,
As you mentioned, “some categories do accept the block, but most just pass through the policy”, could you please clarify on the traffic flow you are testing and specify the source and destination in detail so we can better understand the situation? Also, to investigate further, please provide the unmasked details from your security policy screenshot so we can analyze your configuration more accurately. You may share this information with us via private message.
Additionally, you may enable logging on the policies. This will allow you to check the logs and trace exactly which security policy rule the traffic/event is hitting, also helping pinpoint the necessary adjustments.
Zyxel Tina
0 -
em tese, as regras abaixo nao dereveriam bloquear (funcionar corretamente)?
0 -
certo, movendo para cima nao vai inutilizar a outras regras? qual sequencia deve ser feita?
0 -
-
Hi @DGALDINO,
Thank you for the information!
Since some categories are blocked while others (e.g., Internet Radio/TV) pass through, please verify the classification of unblocked URLs using the tool (screenshot attached below). This confirms how the system categorizes them. If the tested URL does not appear in any category, please let us know. We can further assist by reviewing it on our side.
(Nebula)
Additionally, please note the best practice for firewall rule order:
- For optimal filtering behavior, the most specific and restrictive rules should be placed at the top of your firewall policy list, while more general or permissive rules should be placed lower in the sequence.
Therefore, we also recommend moving the security policies that apply your Content Filter profile to the top of your policy list.
Zyxel Tina
0 -
recortei o conteúdo do site, mas segue que mesmo seguindo orientação de colocar a regra acima de todas outras, algumas politicas ainda não funcionam corretamente.
0 -
what USG are you using? is the firmware upto date?
Might you be using a VPN?
what rule is meant to block the above and is it enabled?
0 -
USG500-FLEX Firmware availability:Up to date (Latest), sem VPN, empresa inteira utiliza Wifi com SSID exclusivo para computador (IBL-PC)
0 -
move rule to the top of the list
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 206 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 522 USG FLEX H Series
- 330 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 290 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.5K FAQ
- 34 Documents
- 86 About Community
- 98 Security Highlight
Freshman Member

Guru Member
Zyxel Employee





