Block facebook by URL instead of category. Not doing SSL Decryption

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Block facebook by URL instead of category. Not doing SSL Decryption

L3 Networker

Hey everyone!  I have a request from one of my other offices to block access to facebook.  The users there are already covered by a policy using a URL Profile that blocks the social networking category.  I also added facebook.com/ and *.facebook.com/ to the block list for that URL profile.  Users are blocked when going to http://www.facebook.com but if they go to https://www.facebook.com they are allowed access and eventually the facebook app takes over.

 

How can I block access to facebook by using URL profiles vs. blocking the application?

 

Thanks!

2 REPLIES 2

L5 Sessionator

URL filtering profile should work. Try adding www.facebook.com in block list. Don't calll anything under Service/ Url Categgory tab in the security policy.

 

Hope this helps.

Cyber Elite
Cyber Elite

Hi

 

Since SSL encrypts all the http communication, the host header information is invisible to the firewall unless you enable decryption. An alternative method to determin e the URL of a website is to look in the ssl certificate used by the server, and determine the URL from there

 

since facebook uses *.facebook.com , you should be able to add that  (sans the / ) to your URL filtering profile and be able to block the website

 

regards

Tom

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 2425 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!