Jump to content

Recommended Posts

Posted

Hi we have hit a small hitch with our testing of Google chrome.

It seems chrome can completely bypass both internal and external filtering and access sites, like Facebook/ yahoo answers etc, simply buy changing the URL to 'https'.

This doesn't happen on all sites - just a few like yahoo answers, youtube etc.

 

We use TMG 2010 internally and a upstream proxy server configured by county.

 

We have also tested it on our Lightspeed system provided by our ISP and it is the same.

 

 

Any Ideas? :confused:

Posted

we have the youtube URL entered into the GPO for chrome.

 

Our Palo Catches urls in both HTTPS/HTTP except youtube as https youtube does not report as being youtube, just a bunch of 1e100.net servers, which is why we have it in the GPO.

Posted (edited)
Blocks fine in Internet Explorer, just in Chrome. Happening on both standalone installs and GPO installs (with chromes GPO configured). Edited by ellsandell
Posted
Strangely we have the opposite issue at the moment, Internet Explorer allows HTTPS but Chrome doesn't. Lightspeed have told us it's due to a backup IP service IE uses and they are working on a fix.
Posted
Strangely we have the opposite issue at the moment, Internet Explorer allows HTTPS but Chrome doesn't. Lightspeed have told us it's due to a backup IP service IE uses and they are working on a fix.

 

Scratch that, I think we have a filtering issue generally, Chrome intermittently allows https sites like encrypted google (which means image searches without safe search).

Posted

We have had major issues with the Google changing to SSL search last year as the Bluecoat Proxy / Filter is unable by default to inspect the SSL search string and then rewrite the URL to force safe search.

So we ended up approaching it two ways. With Google Apps for Education we force safe search through their options - when the kids are signed into Google as the school accounts then safe search is enforced.

If they don't bother to sign in we have had to do SSL interception on ALL Google domains so that we can intercept / decrypt and then force safe search. This of course caused https errors to fire off everywhere on initial testing as effectively we are doing man in the middle SSL - - so we push the Bluecoat SSL cert out to our desktops via GPO as a trusted Cert and then place the cert on the LMS and ask the kids on mobile devices to install manually.

Bit of brute force but we now can enforce safe search.

 

Also - interested to see how other products / schools do youtube SSL filtering as the problem we have is that without SSL interception - Bluecoat can only see the IP being returned to the client not the requested URL - and all traffic from Google, whether from Youtube, Google, Google Video etc can all come from a very similar but random IP range. That is sometimes simple search traffic (google.com) is coming from the same IP range as Youtube traffic - hence Bluecoat categorises this SSL traffic as simply Google. Hence we can't block it otherwise we end up blocking all Google traffic. So we have to use SSL interception.

 

Interested to hear how other vendors or school are tackling https://youtube or safe search. Note - https://www.facebook.com etc is fine as the IP range being returned is known and classified by bluecoat correctly as Facebook..it is only Google / Youtube that gives us this issue.

 

Of course - we have now discovered that SSL interception on Google apparently breaks Google Chrome syncing - so now looking into that...sigh...

Wally

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...