- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Blocking monster in URL Webfilter
Hello,
we have an issue with blocking hdfull.monster. We tried in Webfilter and URL filter and it would not work. Checking nslookup there are Cloudflare IPs and comparing with the test sessions I see other Cloudflare IPs.
Any suggestion how to block this video stream monster?
Thanks!
- Labels:
-
FortiGate
-
Security profile
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Roland
Can you share the web filter you are using?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure which one you are using, Certification Inspection or Deep Inspection.
And please share your configuration about URL Filter and web filter (I assume you mean Category based Filter).
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just did a quick test with Certification Inspection and URL Filter, it worked for me:
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am seeing a similar issue with Cloudflare sites.
Certificate Inspection and URL Filter are being used but the firewall does not even see the URL at all, only the IPs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Probably due to ECH. Check this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I just found some documentation about ECH from Cloudflare. I will check out this link, thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are on 7.2, doesn't look like those options are available. Guess we will have to deal with it unless there is some other way.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please see the screenshots I provided for my testing. It's nothing to do with ECH.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not sure...I am not even seeing the traffic in the Logs when searching for the URL. I can see the IP being hit but does not show the Destination URL. It shows "cloudflare-ech.com".
At least for my particular case.
