kennysarmy Posted July 8, 2025 Posted July 8, 2025 I've just seen students searching for "core ball" and seen them click the returned links, the page opens and they are able to waste time playing the game, if I test with a test account I get the same results, with the game open and pressing to refresh the page gets blocked. What's going on, shouldn't smoothwall block the page on launch? I've had to block the search term "core ball" but this is less than ideal. Can anyone else with a smoothwall on-site box confirm the above behaviour. This is the link directly to the game. https://www.arealme.com/coreball/en/ We have https://www.arealme.com blocked But my searching for core ball and following the link returned by Google the site is accessible @tom_newton
tom_newton Posted July 8, 2025 Posted July 8, 2025 I'll take a look as soon as I can, I have raised it with the relevant team. 1
tom_newton Posted July 8, 2025 Posted July 8, 2025 Can you ticket it too - good chance it's config related 1
tom_newton Posted July 8, 2025 Posted July 8, 2025 Be some new rules to catch this more completely tomorrow morning 1
kennysarmy Posted July 9, 2025 Author Posted July 9, 2025 Searched for "a real me" as a test student and was then able to click the link to a blocked site Ticket 605506 opened.
kennysarmy Posted July 9, 2025 Author Posted July 9, 2025 15 minutes ago, BOOT3988 said: Classic 'QUIC not blocked' symptom. I believe that's in place...
BOOT Posted July 9, 2025 Posted July 9, 2025 Need to block via the firewall too. https://kb.smoothwall.com/hc/en-us/articles/360002136884-Prevent-QUIC-on-your-network-for-web-filtering
kennysarmy Posted July 9, 2025 Author Posted July 9, 2025 Ours looks like this.... Not sure why it's been disabled 😕
tom_newton Posted July 9, 2025 Posted July 9, 2025 No, no proxy I know of can handle QUIC - the only way to handle it is to do filtering in browser like Smoothwall cloud.
mavhc Posted July 9, 2025 Posted July 9, 2025 Is it impossible, or just no one's done it yet? Same question for TLS 1.3 with ECH
PaddyNewman Posted July 11, 2025 Posted July 11, 2025 That is ECH as far as I can see, I recognise the domain from a support case. https://www.nslookup.io/domains/www.arealme.com/dns-records/https/
Joeloman Posted July 11, 2025 Posted July 11, 2025 In Smoothwall you can block ECH https://kb.smoothwall.com/hc/en-us/articles/16651254132252-Ensure-BYO-devices-with-Encrypted-Client-Hello-ECH-are-filtered
ibpalle Posted July 14, 2025 Posted July 14, 2025 Just to mention - the content modification for removing QUIC header will not work if QUIC is already in use - that's why the QUIC blocking in the firewall is important.
mavhc Posted July 14, 2025 Posted July 14, 2025 But if you're decrypting the TLS anyway, why do you need to block quic and ech?
ibpalle Posted July 14, 2025 Posted July 14, 2025 9 minutes ago, mavhc said: But if you're decrypting the TLS anyway, why do you need to block quic and ech? If the browser is in QUIC mode, then traffic wont be passing through the proxy and thus won't be inspected. With the cloud filter extension, filtering is done in the browser, after the browser has received/decrypted the traffic so TLS inspection and QUIC isn't relevant in that case.
mavhc Posted July 14, 2025 Posted July 14, 2025 QUIC mode ignores the proxy settings? How does it work when the proxy is the only way onto the internet?
ibpalle Posted July 14, 2025 Posted July 14, 2025 16 minutes ago, mavhc said: 3 minutes ago, mavhc said: QUIC mode ignores the proxy settings? How does it work when the proxy is the only way onto the internet? QUIC is UDP traffic. Proxies don't intercept UDP. Not sure if that's possible with UDP being connectionless.
mavhc Posted July 14, 2025 Posted July 14, 2025 Looking it up there's a lot of references to https://datatracker.ietf.org/wg/masque/about/ https://quic-go.net/docs/connect-udp/ https://blog.cloudflare.com/unlocking-quic-proxying-potential/
kennysarmy Posted July 15, 2025 Author Posted July 15, 2025 Upon testing in ticket #605506 we found that the 'arealme' domain was calling 'www-arealme-com.webpkgcache.com.' 'www-arealme-com.webpkgcache.com' is categorised under Search Engines, rather than Humour and Distractions like 'arealme.com' 1
sigma Posted July 15, 2025 Posted July 15, 2025 Netsweeper has that categorized as "Technology", so local block applied for now. I seem to think it's blocked in Impero for us in any case.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now