Skip to main content
Mbutler522010
New Member
October 27, 2015
Solved

How do I block specific "sites.google.com"

  • October 27, 2015
  • 3 replies
  • 65128 views

We have the google FQDN's opened per their suggestion ( https://support.google.com/a/answer/2589954?hl=en ) and ( https://support.google.com/drive/answer/6163291 )

 

the kids have discovered a number of gaming sites on google homepages, all seem to be named "unblocked games" i.e.

https://sites.google.com/site/unblockedgames4me

https://sites.google.com/site/unblockedgames77

https://sites.google.com/site/punblockedgames/

 

The problem is that blocking google by address doesn't seem to work as every request seems to use a different one, and I don't know why but I don't seem to be able to block by name.

 

I put in a simple IPV4 policy, source = any,  Destination = "sites.google.com/site/unblockedgames4me",  block

and it doesn't work.  because it is a block there is no SSL inspection or anything like that....

 

When I look at the log there is nothing that says "sites.google.com/site/unblockedgames4me" just "encrypted-tbn1.gstatic.com" but I don't want to block all of google, just the few sites.

 

Can anyone help?

Best answer by AlexFeren

michellem812 wrote:

If I enable Full (deep) inspection, then Google complains about HSTS issues. How did you get past that issue?

[size="2"]

[/size]

[size="3"]See "config ssl-exempt" below.[/size]

 

FG60C (root) # show firewall ssl-ssh-profile "Deep-inspection with HSTS Exception" config firewall ssl-ssh-profile     edit "Deep-inspection with HSTS Exception"         set comment "Deep inspection!"             config https                 set ports 443             end             config ftps                 set ports 990             end             config imaps                 set ports 993             end             config pop3s                 set ports 995             end             config smtps                 set ports 465             end             config ssl-exempt                 edit 1                     set type address                     set address "*.adobe.com"                 next                 edit 2                     set type address                     set address "android"                 next                 edit 3                     set type address                     set address "apple"                 next                 edit 4                     set type address                     set address "appstore.com"                 next                 edit 5                     set type address                     set address "citrixonline"                 next                 edit 6                     set type address                     set address "dropbox.com"                 next                 edit 7                     set type address                     set address "Gotomeeting"                 next                 edit 8                     set type address                     set address "icloud"                 next                 edit 9                     set type address                     set address "itunes"                 next                 edit 10                     set type address                     set address "skype"                 next                 edit 11                     set type address                     set address "swscan.apple.com"                 next                 edit 12                     set type address                     set address "update.microsoft.com"                 next                 edit 13                     set type address                     set address "HSTS"                 next             end     next end

 

  FG60C (root) # show firewall addrgrp HSTS config firewall addrgrp     edit "HSTS"         set member "wikipedia" "Google"     next end

 

FG60C (root) # show firewall addrgrp Google config firewall addrgrp     edit "Google"         set member "*.google.com.au" "*.google.com"     next end

 

FG60C (root) # show firewall address *.google.com.au config firewall address     edit "*.google.com.au"         set type fqdn         set fqdn "*.google.com.au"     next end FG60C (root) # show firewall address *.google.com config firewall address     edit "*.google.com"         set type fqdn         set fqdn "*.google.com"     next end

3 replies

gschmitt
New Member
October 28, 2015

Don't use a FQDN Object for Webfiltering

Please go to Security Profiles > Webfilter and select your used Webfilter

Check Enable URL Filter and click Create New

Enter your URL, make sure Enable is checked and hit OK and Apply

Make sure the Webfiltering Profile is selected for your internal to wan policy

Mbutler522010
New Member
November 3, 2015

unfortunately that doesnt work. I tried it, the logs showed 2 blocked packets, then success to a different address and the website came up. I am going to have to open a support ticket on this I think.

Allwyn_Mascarenhas
New Member
November 4, 2015

Just go through this and you will get the idea on how to do it.

 

What you did failed exactly because it had no ssl inspection as you said. Also don't forget to block google's new quic protocol.

 

so many people are struggling with this because of their quic thing now..we should have a sticky post with a checklist for webfiltering.

davidahaha93
New Member
June 22, 2019

I have the same problem as you. Children often visit the website [link]https://sites.google.com/site/unblockedgamesfun66,[/link] which I can't stop

Help me!

schoolana
New Member
September 27, 2019

please help block this sites :https://sites.google.com/view/unblockable-games

                                         https://sites.google.com/site/unblockedgame67/

clara
New Member
December 7, 2019

I've been trying for days, but I couldn't ! https://sites.google.com/site/allunblockedgames77 please help me.

monroedavidk30
New Member
August 3, 2025

I have the same problem as you. Children often visit the website

i want to block these and this one also 

https://sites.google.com/view/drive-m-7-home