Problem URL-Filter onedrive urls

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Problem URL-Filter onedrive urls

L2 Linker

Hello everybody,

 

I use url-list from urlhaus. If I test some entries, I got a problem with onedrive-urls like this:

 

onedrive.live.com/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi

This url should be blocked by urlfilter on the firewall. But it was not blocked. I can download the file. Also I can not see any entries in url-filter-log. Thanks for any help or hints.

 

R. Boehm

1 accepted solution

Accepted Solutions

@RalfBoehm actually you are partly wrong. You are right that normally URL filtering works for http and https traffic, but configuration of tls decryption is required to see the full URL. Without decryption the firewall only sees "onedrive.live.com" and this obviously will not match with the url you wrote in the first post in this topic.

View solution in original post

5 REPLIES 5

Cyber Elite
Cyber Elite

@RalfBoehm,

Do you have decryption enabled for untrust traffic? 

No. Also I think, it is not relevant in this case. URL's are not encrypted. Normaly URL-Filter works for http- and https-traffic, independently of decryption. Or I am wrong?

@RalfBoehm actually you are partly wrong. You are right that normally URL filtering works for http and https traffic, but configuration of tls decryption is required to see the full URL. Without decryption the firewall only sees "onedrive.live.com" and this obviously will not match with the url you wrote in the first post in this topic.

Thank you for your hint, I have configured decryption, and now it is worked as expected. But what is the reason for that difference? I thought, url is every time normaly text, and the URL-Filter compare exactly the called url?

 

MfG Boehm

@RalfBoehm,

Nope. Without decryption the only thing that the firewall can actually read is the domain in the ClientHello request, you can't see the full URL as the field is encrypted in HTTPS traffic. 

  • 1 accepted solution
  • 4831 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!