security policy does not block traffic

Options
DGALDINO
DGALDINO Posts: 11 image  Freshman Member
First Comment Friend Collector

I created the blocking rules based on the content filter categories, but they are not being blocked. For example, online radios (to reduce bandwidth usage) are not being blocked, some categories do accept the block, but most just pass through the policy.

image.png
«1

All Replies

  • PeterUK
    PeterUK Posts: 4,250 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited December 3

    You likely have to move the rule to the top as any rule above could be allowing the traffic before it gets to the content filter rule.

  • Zyxel_Tina
    Zyxel_Tina Posts: 425 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @DGALDINO,

    As you mentioned, “some categories do accept the block, but most just pass through the policy”, could you please clarify on the traffic flow you are testing and specify the source and destination in detail so we can better understand the situation? Also, to investigate further, please provide the unmasked details from your security policy screenshot so we can analyze your configuration more accurately. You may share this information with us via private message.

    Additionally, you may enable logging on the policies. This will allow you to check the logs and trace exactly which security policy rule the traffic/event is hitting, also helping pinpoint the necessary adjustments.

    Zyxel Tina

  • DGALDINO
    DGALDINO Posts: 11 image  Freshman Member
    First Comment Friend Collector

    em tese, as regras abaixo nao dereveriam bloquear (funcionar corretamente)?

  • DGALDINO
    DGALDINO Posts: 11 image  Freshman Member
    First Comment Friend Collector

    certo, movendo para cima nao vai inutilizar a outras regras? qual sequencia deve ser feita?

  • Zyxel_Tina
    Zyxel_Tina Posts: 425 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers First Comment

    Hi @DGALDINO,

    Thank you for the information!

    Since some categories are blocked while others (e.g., Internet Radio/TV) pass through, please verify the classification of unblocked URLs using the tool (screenshot attached below). This confirms how the system categorizes them. If the tested URL does not appear in any category, please let us know. We can further assist by reviewing it on our side.

    (Nebula)

    image.png

    Additionally, please note the best practice for firewall rule order:

    • For optimal filtering behavior, the most specific and restrictive rules should be placed at the top of your firewall policy list, while more general or permissive rules should be placed lower in the sequence.

    Therefore, we also recommend moving the security policies that apply your Content Filter profile to the top of your policy list.

    Zyxel Tina

  • DGALDINO
    DGALDINO Posts: 11 image  Freshman Member
    First Comment Friend Collector
    edited December 5

    recortei o conteúdo do site, mas segue que mesmo seguindo orientação de colocar a regra acima de todas outras, algumas politicas ainda não funcionam corretamente.

    image.png image.png
  • PeterUK
    PeterUK Posts: 4,250 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited December 5

    what USG are you using? is the firmware upto date?

    Might you be using a VPN?

    what rule is meant to block the above and is it enabled?

  • DGALDINO
    DGALDINO Posts: 11 image  Freshman Member
    First Comment Friend Collector

    USG500-FLEX  Firmware availability:Up to date (Latest), sem VPN, empresa inteira utiliza Wifi com SSID exclusivo para computador (IBL-PC)

    image.png Captura de tela 2025-12-05 121330.png image.png
  • PeterUK
    PeterUK Posts: 4,250 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    move rule to the top of the list

Nebula Tips & Tricks