Solved

Sonicwall HTTPS filtering

Posted on 2014-03-06
4
451 Views
Last Modified: 2014-03-06
I recently acquired a sonicwall 250 NSA with most licenses but the DPI-SSL (at the time I did not know the impact this license had) and  I came across a problem when filtering content to my users.. well https is not filtered at all... and lots of sites use https. So I tried to create a firewall rule that would deny https to some users but, as it turns out . you cant do this so... does anyone know a workaround or a method to if possible filter https (yes I tried the Enable HTTPS Content Filtering checkmark)  and if not possible to deny traffic to some users at the https service and allow others...

Thanks!
0
Comment
Question by:xqualo
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 20

Expert Comment

by:carlmd
ID: 39909491
0
 

Author Comment

by:xqualo
ID: 39909617
Looks good however I'm looking to deny all https access to some users not to a special website.  the other 3 links are about how to use a blacklist and DPI-SSL license.. it does help but it doesnt solve the problem as a whole :)  Thanks!
0
 
LVL 20

Accepted Solution

by:
carlmd earned 500 total points
ID: 39909680
You should be able to do that by setting up a firewall rule. Depending upon which list is larger, the ones you want to block, or the ones you want to allow, would determine the best way to go. For example, assume you want to block 3 pc's (by ip or mac address), first define each one as an Address Object, then add all three to a Group. Now create a rule for the LAN to WAN zone that blocks are traffic on port 443 for the specific group. Make sure this rule is above (higher priority) then the permit all (any any) rule. That should do it.

If you need instructions to do this please advise.
0
 

Author Closing Comment

by:xqualo
ID: 39909779
Thanks!
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question