Slarty66 Posted February 12 Posted February 12 We have a meraki firewall and for some reason we cannot block https://definitelyscience.com/ It is in Content Filtering and in the students policy. We have Games in the categories and we have layer 7 Gaming blocked. It will block on some of the student computers in the academy but we still have a lot of machines that just wont block this website. It's a real puzzle and its strange as every other game site is blocked!
tom_newton Posted February 12 Posted February 12 The site supports QUIC, HTTP3 - so likely these are the culprits 1
Slarty66 Posted February 12 Author Posted February 12 2 minutes ago, tom_newton said: The site supports QUIC, HTTP3 - so likely these are the culprits How do we block these ?
Davit2005 Posted February 12 Posted February 12 (edited) Do you have user based policy, is it not recognising user or some sort of cache in the IP to user mapping. What do the logs look like is it the expected user showing in the logs? Is the site allowed for staff or other user groups. Edited February 12 by Davit2005
DGardiner Posted February 12 Posted February 12 4 minutes ago, Slarty66 said: How do we block these ? for quic: block port UDP 443/80 on the firewall as for doh/etc you will need to check with your filter/firewall for things to try as its usually a layered approach 2
Slarty66 Posted February 12 Author Posted February 12 22 minutes ago, Davit2005 said: Do you have user based policy, is it not recognising user or some sort of cache in the IP to user mapping. What do the logs look like is it the expected user showing in the logs? Is the site allowed for staff or other user groups. User based policy. The expected users are showing in the logs showing they are being blocked but it also shows events being dropped. 1
Slarty66 Posted February 12 Author Posted February 12 44 minutes ago, DGardiner said: for quic: block port UDP 443/80 on the firewall as for doh/etc you will need to check with your filter/firewall for things to try as its usually a layered approach As it's half term next week we can block the ports when students aren't here.
tom_newton Posted February 12 Posted February 12 Doesnt look like that site supports ECH, but you should definitely put in some defences against that if you can, as others might. 1
KDW1987 Posted March 6 Posted March 6 (edited) This is because the firewall is not doing decryption. If you are not decrypting the traffic you wont be able to fully block web applications. To meet kcsie you really need a holistic solution which includes URL, DNS and layer 7 application control as without decryption enabled across all 3 features as a minimum now. Plus the new DFEs AI filtering standards now mean we need tools that can provide dlp and casb tools to meet those standards too. Edited March 6 by KDW1987 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now