Slarty66 Posted September 15, 2025 Posted September 15, 2025 We use a Meraki firewall in our academy, we recently noticed students getting pass the filtering for one particular games site azgames. Looking at the logs of computers students could do this on we noticed that students could bypass the URL blocklist by hitting the F5 key multiple times until it let them access the site. This only happens with this one website a real puzzle as it blocks every other website on our blocklist. Anyone have this problem?
BOOT Posted September 15, 2025 Posted September 15, 2025 Are you blocking QUIC? It's most likely that. 1
Davit2005 Posted September 15, 2025 Posted September 15, 2025 (edited) 1 hour ago, Slarty66 said: We use a Meraki firewall in our academy, we recently noticed students getting pass the filtering for one particular games site azgames. Looking at the logs of computers students could do this on we noticed that students could bypass the URL blocklist by hitting the F5 key multiple times until it let them access the site. This only happens with this one website a real puzzle as it blocks every other website on our blocklist. Anyone have this problem? So the Meraki seems to get over whelmed and allow anyway? Does the same happen for other blocked sites? I would certainly look at the log files for traffic and system and see if their is any correlation. Edited September 15, 2025 by Davit2005
Slarty66 Posted September 15, 2025 Author Posted September 15, 2025 55 minutes ago, BOOT3988 said: Are you blocking QUIC? It's most likely that. I will have a word with our service engineer as they run that side of our firewall. I suspect it's that.
PaddyNewman Posted September 15, 2025 Posted September 15, 2025 Are you decrypting traffic? If not, you only have to beat the RST packet which F5 can do if you hammer it. It was a weird bug raised a long time ago but not with Meraki, more Netsweeper and even then, an old version. 2
Slarty66 Posted September 17, 2025 Author Posted September 17, 2025 On 15/09/2025 at 14:21, PaddyNewman said: Are you decrypting traffic? If not, you only have to beat the RST packet which F5 can do if you hammer it. It was a weird bug raised a long time ago but not with Meraki, more Netsweeper and even then, an old version. We used to have a Palo Alto which would decrypt traffic. The Meraki doesn't and it would seem this bug is know. We tried disabling QUIC and it works to a point, the more persistent students will still get by this. We've made teachers aware of this so it's more classroom management. Students shouldn't be hitting F5 constantly in a lesson anyway!
PaddyNewman Posted September 17, 2025 Posted September 17, 2025 (edited) I would recommend getting a web filter that does decrypt, otherwise you can't really meet safeguarding requirements. Having some form of MITM means you can't beat a reset, unless the proxy is useless, as it's the one who makes the connection on your behalf, can't be served the wrong cert back and it's likely denied before the connection is even made at the other end. Plus, you cant really filter without inspection. That's the worst bit. Edited September 17, 2025 by PaddyNewman 1
Slarty66 Posted September 17, 2025 Author Posted September 17, 2025 2 minutes ago, PaddyNewman said: I would recommend getting a web filter that does decrypt, otherwise you can't really meet safeguarding requirements. Having some form of MITM means you can't beat a reset, unless the proxy is useless, as it's the one who makes the connection on your behalf, can't be served the wrong cert back and it's likely denied before the connection is even made at the other end. Plus, you cant really filter without inspection. That's the worst bit. We have Senso as well so that covers our web filtering. But yes to be honest we thought the Palo alto was more flexible than the Meraki. 1
PaddyNewman Posted September 17, 2025 Posted September 17, 2025 I've never really seen any Meraki kit outside of MX / WiFi stuff, personally I'd be wanting a proper filtering item and firewall, but not sure of your scenario etc. Senso should be decrypting and stopping the refresh also, so that would be a mild concern for me but something to potentially think about. 1
Davit2005 Posted September 17, 2025 Posted September 17, 2025 Have been working with Palo firewalls for about 9 years now and I am a fan as far as the firewall but I don't think you can match any combined FW and filter with the separate solutions from different vendors.
KDW1987 Posted March 6 Posted March 6 Cisco Meraki aren't listed on the UK safer Internet centres list of approved web filter vendors for education are they ?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now