Top Blocked Sites by URL - Identify the User who has tried to access the blocked / restricted page

Electra
Just browsing

Top Blocked Sites by URL - Identify the User who has tried to access the blocked / restricted page

Hi i have looked through the topics and trying to identify a user who has tried to access a blocked URL. I.e. xxx on SSID. so we can potentially block this user on all sites

I can see access attempts to x URl (Category) and how many times, but would like to find out the user identity. (This is taken form the Organisation > Summary report.

Thanks Chris

3 Replies 3
Jonathan-S
Meraki Employee
Meraki Employee

Hi Chris,

 

Since you had mentioned an SSID, is my assumption that you are leveraging a Cisco Meraki MR wireless access point correct here? If so, which model(s) are you currently using within your Organization?

 

Additionally, are you leveraging any other Cisco Meraki gear within your network(s)?

 

Thanks!

Jonathan

If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.
Electra
Just browsing

Hi thank you for your reply, yes we have MR33, MR42, MR52

 

With MX67, MX100, MX250

Jonathan-S
Meraki Employee
Meraki Employee

Hi Chris,

 

Thank you for supplying that additional information.

 

Starting with our new Wi-Fi 6 MR APs, when leveraging Layer 7 block rules for specific (NBAR) categories, you can view instances of these blocks from within the Event Log, including the specific wireless client that attempted to access a given blocked category of websites. Since the MR models that you mentioned are from our Wi-Fi 5 (Wave 2) line, we unfortunately would not be able to leverage this option at this time. It is also important to note that these Event Log entries would only trigger when blocking by website category and would not work for say a custom Layer 7 HTTP hostname definition.

 

If, however, you are leveraging the "Advanced Security" or "SD-WAN Plus" MX licensing tier on your MXes, you may still be able to achieve what you are after here by configuring Content Filtering rules on the MX. You would see Event Log entries when these rules are triggered, including the specific client that was attempting to access the blocked website and/or blocked category. The use of Group Policies from within your Meraki Dashboard Network would allow for granularity of these rules as needed. Finally, do note that leveraging the Content Filtering features of the MX would require that the downstream SSID(s) in question are configured in bridge mode ("External DHCP server assigned") as "NAT mode" would simply report the downstream MR AP as the client as opposed to the actual wireless end-client.

 

I hope this helps explain your options a bit. Feel free to call into our 24/7 Enterprise Support hotline if you need further assistance with any of these configurations.

 

Jonathan

If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.