URL Blocking for Home Edition

Comments

2 comments

  • SVN Support Team

    Hi Jonathan,

    Sorry for the late reply. I'm sorry to hear that. For URL blocking, the TLS session needs to be inspected. Zenarmor offers this feature with an SSE or higher license tier.

    0
    Comment actions Permalink
  • Peter

    I don't agree.  Using the home edition you have the ability to do what might be called lite-weight TLS inspection which is sufficient for inspecting the medadata and allowing or blocking based on SNI.  Full TLS inspection isn't required.

    Domains can be blocked in two ways.  
     - Within the web controls section a custom category can be added.
     - The URL can be blocked as an exception.  A whitelist exception can also be added.

    Note: you cannot block based on any part of the path, just the domain and sub-domains. I believe that would require full TLS inspection to block based on path.

    Note also, that you should enable the following blocks to ensure that the Quic protocol and DNS encryption do not prevent the inspection of the SNI.  Otherwise traffic using these means below will not be blocked.


    Web Controls:
    Block TLS Encrypted Client HELLO (ECH)

    App Controls:
    Media Streaming > Quic UDP Connection
    Network Management > DNS over HTTPS
    Network Management > DNS over TLS

     

     

    0
    Comment actions Permalink

Please sign in to leave a comment.

Powered by Zendesk