This article describes the method to block Google.com and Facebook.com using CFS 4.0.
CFS examines the Server Extensions field in the Client Hello message and/or the CN in the Server Hello message to block HTTPS sites. HTTP sites are blocked by examining the Host field of the GET request. The following sections describe the methods involved in blocking both HTTP and HTTPS google.com and facebook.com.
Enabling CFS and HTTPS Content Filter Globally


Creating URI List Object

Creating CFS Profile Object

Creating CFS Policy

NOTE: Make sure the customized policy always has the higher priority than the CFS Default Policy so that it can be effective.
Log Messages



The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.
Enabling CFS and HTTPS Content Filter Globally

Creating URI List Object

Creating CFS Profile Object

Creating CFS Policy

NOTE: Make sure the customized policy always has the higher priority than the CFS Default Policy so that it can be effective.
Log Messages


