Content Filtering Not working

Riser
Getting noticed

Content Filtering Not working

Hey fam,

 

We are trying to test the URL Filtering on Meraki to see how it works but it doesn't seem to block any sites. 

 

Someone suggested I do this: content filtering relies on the client using HTTP for web traffic, but your client uses the QUIC protocol instead. To resolve the issue, you can create a Layer 3 firewall rule that blocks UDP ports 80 and 443 (which the QUIC protocol uses) which also didn't seem to work.

 

Any idea. Images are attached

 

Riser_0-1720033391950.png

Riser_2-1720033427483.png

 

17 Replies 17
alemabrahao
Kind of a big deal
Kind of a big deal

Is it not working to access via App or Web Browser?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Riser
Getting noticed

I can still access the sites on the Web Browser.

alemabrahao
Kind of a big deal
Kind of a big deal

Try using these URLs.

 

*.facebook.com

*.akamaihd.net 

*.fbcdn.net

*.fb.me

*.fbsbx.com

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Riser
Getting noticed

Facebook is still working. No, any luck.

Riser
Getting noticed

Riser_0-1720034486708.png

 

alemabrahao
Kind of a big deal
Kind of a big deal

Are you sure that it's not web browser cache?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Riser
Getting noticed

I cleared the cache but no luck at all. 

Inderdeep
Kind of a big deal
Kind of a big deal

here you can troubleshoot 

https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Content_Filtering/Conten....

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com
ww
Kind of a big deal
Kind of a big deal

Looks like the content filter block url list is broken in latest firmware

Riser
Getting noticed

I kind of think so too because its not blocking an URL.

ww
Kind of a big deal
Kind of a big deal

Hmm it does seem to work, but not consistent after i put in or remove urls.

Could you try inprivate browser tab.

Also try maybe reboot mx if possible. 

RaphaelL
Kind of a big deal
Kind of a big deal

yeah I was going to suggest to reboot the MX to clear the active sessions / flows.

Riser
Getting noticed

Did reboot but still didn't work.

alemabrahao
Kind of a big deal
Kind of a big deal

I would suggest you open a support case.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Inderdeep
Kind of a big deal
Kind of a big deal

but any notification and anything heard from Meraki on this ??

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com
haupt
Meraki Employee
Meraki Employee

Hey community members, thank you for bringing this to our attention. Can you please open a support case so that we can investigate? At the moment, we are not aware of any widespread issue causing these problems.

Brash
Kind of a big deal
Kind of a big deal

No comment on the content filtering specifically, but one thing to note about firewall rules is that when using an FQDN, the MX must intercept a DNS lookup for that domain before the rule will apply.
For example, if the client already has the domain resolved in its cache and you add the firewall rule, the rule won't apply until the MX see's a DNS lookup for the domain.
Solved: Meraki MX Firewall with FQDN - The Meraki Community

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels