- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Content Filtering Not working
Hey fam,
We are trying to test the URL Filtering on Meraki to see how it works but it doesn't seem to block any sites.
Someone suggested I do this: content filtering relies on the client using HTTP for web traffic, but your client uses the QUIC protocol instead. To resolve the issue, you can create a Layer 3 firewall rule that blocks UDP ports 80 and 443 (which the QUIC protocol uses) which also didn't seem to work.
Any idea. Images are attached
- Labels:
-
Firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it not working to access via App or Web Browser?
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can still access the sites on the Web Browser.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try using these URLs.
*.facebook.com
*.akamaihd.net
*.fbcdn.net
*.fb.me
*.fbsbx.com
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Facebook is still working. No, any luck.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you sure that it's not web browser cache?
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I cleared the cache but no luck at all.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
here you can troubleshoot
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Looks like the content filter block url list is broken in latest firmware
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I kind of think so too because its not blocking an URL.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hmm it does seem to work, but not consistent after i put in or remove urls.
Could you try inprivate browser tab.
Also try maybe reboot mx if possible.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yeah I was going to suggest to reboot the MX to clear the active sessions / flows.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did reboot but still didn't work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would suggest you open a support case.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
but any notification and anything heard from Meraki on this ??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey community members, thank you for bringing this to our attention. Can you please open a support case so that we can investigate? At the moment, we are not aware of any widespread issue causing these problems.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No comment on the content filtering specifically, but one thing to note about firewall rules is that when using an FQDN, the MX must intercept a DNS lookup for that domain before the rule will apply.
For example, if the client already has the domain resolved in its cache and you add the firewall rule, the rule won't apply until the MX see's a DNS lookup for the domain.
Solved: Meraki MX Firewall with FQDN - The Meraki Community
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are also having content filtering issues at 2 schools. Students are getting access to pornographic and gaming sites. We currently have this escalated to developers. Our content filtering is intermittent, we have applied a layer 3 firewall rule to block QUIC protocol on UDP 443 and 80 as recommended on a few forum posts and from the support recommendation, but it has not made any improvements. We are at a loss here and Meraki support just keeps going in circles asking us to go back onsite to collect more logs and they just keep recommending us to block those same ports. At this point I am going in circles with no resolution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Regarding content filters, if you use the Quic protocol, it may not be possible to block it due to the nature of the protocol. This is described in the Meraki documentation. Therefore, it is possible to block such communications by blocking UDP 443 with an L3 firewall, but in that case, if a client terminal uses Quic for web communication, it may affect the communication. Therefore, it may be possible to avoid this by disabling Quic on the client terminal, but I thought that it would be difficult to do so easily if the scale is large. Also, this may not work in the case of umbrella web policy, and the workaround was to disable Quic.
https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Content_Filtering/Conten...
https://support.umbrella.com/hc/en-us/articles/360051232032-What-Are-the-Problems-with-Google-Servic...
