MrLudwig Posted January 23, 2018 Posted January 23, 2018 Has anyone managed to successfully block social media mobile apps such as Facebook, FB Messenger, Snapchat, Whatsapp etc? I'm trying to block these on our student Wifi network for BOYD devices so can't really touch the devices themselves. We use a Meraki managed wifi system and have Exa's Surfprotect Quantum filtering in place on our Internet connection, so in theory it should be relatively straight forward. At least that's what I thought. I've got a category block on social media set in the filter, plus numerous firewall rules set up in the Meraki firewall for url's that I've found mentioned in various forum posts that suggest they work, but stuff is still getting through. I've had partial success, mainly with iOS version of the apps, but FB on Android for example not so much. If I clear the FB app's data/cache, then it can't log back in which is great. But if it is already logged into an account (which will be the case for pretty much all the BOYD devices), then it can happily carry on as normal and get new content, not just the stuff it already has cached. I've seen some have success using DNS poisoning, but I'd rather not have to set up a new DNS server for this when we already have a filtering solution and firewall capabilities on the wifi that should be able to do the job. I also realise that students could resort to their mobile data connection and bypass the restrictions, but that's completely out of my control so not my responsibility. I'm up to nearly 40 firewall rules now for just a few apps (Meraki doesn't seem to like wildcards) and starting to lose patience a little, so please for the sake of my sanity, please help. Thanks.
atcoates Posted January 23, 2018 Posted January 23, 2018 Is this what you have applied for your byod SSID?
atcoates Posted January 23, 2018 Posted January 23, 2018 Is this what you have applied for your byod SSID? [ATTACH=CONFIG]47268[/ATTACH] Meraki support can also help if the rules aren't working.
SchoolsBroadband Posted January 23, 2018 Posted January 23, 2018 Do you have an onsite Fortigate firewall for use with Exa Surfprotect Quantum? If so unless I'm missing something and you've got the UTM features enabled on the Fortigate then this comes with App control and you can block all or bits of facebook.We can certainly do it on our Fortigate firewalls as standard. Dave
MrLudwig Posted January 23, 2018 Author Posted January 23, 2018 Is this what you have applied for your byod SSID? [ATTACH=CONFIG]47268[/ATTACH] Meraki support can also help if the rules aren't working. Yes, plus added a load of additional rules such as fbcdn.net, connect.facebook.net, api.facebook.com etc.
atcoates Posted January 23, 2018 Posted January 23, 2018 Might be worth raising a call with Meraki as it's their rules that aren't working here. 1
MrLudwig Posted January 25, 2018 Author Posted January 25, 2018 Might be worth raising a call with Meraki as it's their rules that aren't working here. I've logged this with Meraki Support now, will see what they come back with.
MrLudwig Posted January 25, 2018 Author Posted January 25, 2018 Do you have an onsite Fortigate firewall for use with Exa Surfprotect Quantum? If so unless I'm missing something and you've got the UTM features enabled on the Fortigate then this comes with App control and you can block all or bits of facebook.We can certainly do it on our Fortigate firewalls as standard. Dave We do have an onsite Fortigate firewall as part of our Exa connection, although we don't have access to the management interface so can't tell what features have been turned on and what hasn't. We haven't long switched over to Exa from SWGfL so still finding our way around somewhat. Just out of curiosity, how much management access to the firewall and router do you allow from the schools you supply?
atcoates Posted January 25, 2018 Posted January 25, 2018 Maybe the meraki rules are geared towards US domains so that's why they're not working?
SchoolsBroadband Posted January 25, 2018 Posted January 25, 2018 We do have an onsite Fortigate firewall as part of our Exa connection, although we don't have access to the management interface so can't tell what features have been turned on and what hasn't. We haven't long switched over to Exa from SWGfL so still finding our way around somewhat. Just out of curiosity, how much management access to the firewall and router do you allow from the schools you supply? Hi there. It depends it depends on what package you take from us. If your on a shared firewall then we manage this on your behalf but you can have your own dedicated virtual firewall you have full access to and can make any changes yourself. Dave
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now