How to block Google Play Store on Desktop and mobile devices (Android) using App Rules.
10/14/2021 19 People found this article helpful 494,148 Views
Description
How to block Google Play Store on Desktop and mobile devices (Android) using App Rules (Application Firewall).
Resolution
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Feature/Application:
This article describes how to block Google Play Store both on mobile devices and desktops using App Rules.
Note:
- This solution blocks DNS requests / responses only. If Google Play Store is open before enabling this rule, it might allow access. However, when attempting to open afresh, it will be blocked.
- The solution described here will block other Google Services like Google Maps, Hangout etc.
Procedure:
Create Match Object
- Login to the SonicWall Management GUI
- Navigate to the Manage | Objects | Match Objects page.
- Click on Add New Match Object to open the Add/Edit Match Object window.
- Enter a name for this object under Object Name
- Set Match Object Type to Custom Object
- Set Input Representation as Hexadecimal
- Under Content, enter the following hex strings:
- 07616e64726f696407636c69656e747306676f6f676c6503636f6d
Note: This will block access to Play Store when accessed over the Play Store app. - 04706c617906676f6f676c6503636f6d
Note: This will block access to Play Store when accessed over a browser.
- Click on Add
- Click on OK
Create App Rule
- Navigate to the Rules | Application Control page.
- Click on the Add New Policy button to open the Edit App Control Policy window.
- Enter the following information and click on OK.
Note: You could lock it down further by Zone. For example,
- Set Connection Side to Server Side or Both
- Click on Advanced under Direction
- Set From to Any and To to WLAN (Any in case the server is internal)
This will block DNS response from a server on the WAN or LAN.
Testing:
From a mobile device behind the SonicWall, try to open the Play Store app after flushing the DNS cache of the device (mostly done by restarting the device) and you will get the following error in the app. If the device's DNS server is pointed to an internal DNS server, then flush the DNS cache of the server before testing.
The following message will be logged in the SonicWall under Investigate | Event Logs
Resolution for SonicOS 6.2 and Below
The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.
Feature/Application:
This article describes how to block Google Play Store both on mobile devices and desktops using App Rules.
Note:
- This solution blocks DNS requests / responses only. If Google Play Store is open before enabling this rule, it might allow access. However, when attempting to open afresh, it will be blocked.
- The solution described here will block other Google Services like Google Maps, Hangout etc.
Procedure:
Create Match Object
- Login to the SonicWall Management GUI
- Navigate to the Firewall > Match Objects page ( In older SonicOS firmware this page would be under Application Firewall > Match Objects)
- Click on Add New Match Object to open the Add/Edit Match Object window.
- Enter a name for this object under Object Name
- Set Match Object Type to Custom Object
- Set Input Representation as Hexadecimal
- Under Content, enter the following hex strings:
- 07616e64726f696407636c69656e747306676f6f676c6503636f6d
Note: This will block access to Play Store when accessed over the Play Store app. - 04706c617906676f6f676c6503636f6d
Note: This will block access to Play Store when accessed over a browser.
- Click on Add
- Click on OK
Create App Rule
- Navigate to the Firewall > App Rules page.
- Click on the Add New Policy button to open the Edit App Control Policy window.
- Enter the following information and click on OK.
Note: You could lock it down further by Zone. For example,
- Set Connection Side to Server Side or Both
- Click on Advanced under Direction
- Set From to Any and To to WLAN (Any in case the server is internal)
This will block DNS response from a server on the WAN or LAN.
- Enable the check-box Enable App Rules.
Testing:
From a mobile device behind the SonicWall, try to open the Play Store app after flushing the DNS cache of the device (mostly done by restarting the device) and you will get the following error in the app. If the device's DNS server is pointed to an internal DNS server, then flush the DNS cache of the server before testing.
The following message will be logged in the SonicWall under Log > View
Related Articles
Categories