QUIC Protocol Disable methods

Solved
AJAY2
Here to help

QUIC Protocol Disable methods

Hi, 

 

Is there a way we can disable QUIC protocol on the Guest client browsers (Captive portal via Cisco ISE) to ensure Content filtering works as expected on the MX/Firewall ?

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal
6 Replies 6
Brash
Kind of a big deal
Kind of a big deal

This post has some good information about methods to block QUIC traffic

 

https://community.meraki.com/t5/Security-SD-WAN/Block-QUIC-navigation-about-google-protocol/m-p/2681...

BlakeRichardson
Kind of a big deal
Kind of a big deal

This premise of QUIC is good but it creates all sorts of issues with content filtering and SSL inspection. 

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
alemabrahao
Kind of a big deal
Kind of a big deal

Block UDP/443 on MX for Guest VLAN. This is the simplest and most effective method.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Inderdeep
Kind of a big deal
AJAY2
Here to help

Tell me whether blocking on the Zscaler DNS will prevent the QUIC protocol issues?

alemabrahao
Kind of a big deal
Kind of a big deal

Blocking only via Zscaler DNS may reduce some QUIC‑related issues, but it will not reliably prevent QUIC. For consistent results, you need to block QUIC at the network/HTTP proxy level, not just DNS.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels