03/26/2020 992 People found this article helpful 456,977 Views
CFS: Does CFS support HTTPS site blocking?
Question:
Does CFS support HTTPS site blocking?
Resolution/Workaround:
Until SonicOS Enhanced 5.8.0.0, HTTPS Filtering is IP-based. Therefore, IP addresses must be used rather than domain names in the Allowed or Forbidden lists. You can use the nslookup command in a DOS cmd window to convert a domain name to its IP address(es). There may be more than one IP address associated with a domain, and if so, all must be added to the Allowed or Forbidden list.
With the release SonicOS Enhanced 5.8.0.0 HTTPS sites were blocked using HTTPS Content Filtering which is both IP as well as hostname based. SonicWall CFS obtains hostnames (example, google.com) using the following methods:
Note: Unlike HTTP content filtering, HTTPS sites are silently blocked without displaying a CFS block page.