CFS: Does CFS support HTTPS site blocking?

Description

CFS: Does CFS support HTTPS site blocking?

Resolution

Question:

Does CFS support HTTPS site blocking?

Resolution/Workaround:

Until SonicOS Enhanced 5.8.0.0, HTTPS Filtering is IP-based. Therefore, IP addresses must be used rather than domain names in the Allowed or Forbidden lists. You can use the nslookup command in a DOS cmd window to convert a domain name to its IP address(es). There may be more than one IP address associated with a domain, and if so, all must be added to the Allowed or Forbidden list.

With the release SonicOS Enhanced 5.8.0.0 HTTPS sites were blocked using HTTPS Content Filtering which is both IP as well as hostname based. SonicWall CFS obtains hostnames (example, google.com) using the following methods:

  1. Examine SSL Client Hello messages and, if it supports SSL server name extension, it will have hostname included in the SSL Client  Hello. This hostname is used to get rating information.
  2. Another method is to examine Server Hello messages to get certificate Common Names (CN) from the certificate and use the same to get rating information.

Note: Unlike HTTP content filtering, HTTPS sites are silently blocked without displaying a CFS block page.

Related Articles

  • How to create a dedicated user with the least privileges for the SSO agent
    Read More
  • How can I configure BGP (Border Gateway Protocol) with single ISP and advertise your public network?
    Read More
  • Expanded license for A/A Clustering and BGP
    Read More
not finding your answers?