URL Filtering

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

URL Filtering

L2 Linker

I changed some rules around to secure things a little more. I need to allow Netflix/YouTube either by user or subnet because it is now blocked with my changes. What is best practice to create a new policy to do so? I currently have a staff and student URL filtering policy in place.

1 accepted solution

Accepted Solutions

URL filtering happens at layer7 whereas traffic log is typically layer3 type of stuff, so it is perfectly possible to allow a tcp session in traffc logs and then block the url due to url filtering profile. The zebbrowsing session is blocked because the website category is bad, but the tcp communication underneath happens normally (hence an allow in traffic log)

 

It is best practice to build a policy based around User-ID as this will allow your users to all occupy the same IP space without you needing to set reservations to make sure certain people get specific access (and the potential of someone else figuring out the IP and hijacking it to get privileges)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

L2 Linker

I see what I want allow blocked on the URL filtering log but not the Traffic log. Application type Netflix-base for appears allowed in Traffic log but action is block-url in the URL filtering log.

URL filtering happens at layer7 whereas traffic log is typically layer3 type of stuff, so it is perfectly possible to allow a tcp session in traffc logs and then block the url due to url filtering profile. The zebbrowsing session is blocked because the website category is bad, but the tcp communication underneath happens normally (hence an allow in traffic log)

 

It is best practice to build a policy based around User-ID as this will allow your users to all occupy the same IP space without you needing to set reservations to make sure certain people get specific access (and the potential of someone else figuring out the IP and hijacking it to get privileges)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 2537 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!