Community discussions

MikroTik App
Ishikawa
just joined
Topic Author
Posts: 4
Joined: Thu May 19, 2011 3:56 am

Default Deny Web Filtering

Thu May 19, 2011 4:04 am

Is it possible to do default deny web filtering with a RB750G? We want have a list of url's (less than 100) that clients behind the router can access. All other access to the web should be blocked.
Top
blake
Member
Member
Posts: 426
Joined: Mon May 31, 2010 10:46 pm
Location:Arizona

Re: Default Deny Web Filtering

Thu May 19, 2011 5:17 am

Top
Ishikawa
just joined
Topic Author
Posts: 4
Joined: Thu May 19, 2011 3:56 am

Re: Default Deny Web Filtering

Thu May 19, 2011 10:45 pm

Thanks, that's what I was looking for.
Top
Ishikawa
just joined
Topic Author
Posts: 4
Joined: Thu May 19, 2011 3:56 am

Re: Default Deny Web Filtering

Wed May 25, 2011 6:07 am

I realized a proxy solution will not work for HTTPS since it constitutes a MITM attack. Is there any way to filter HTTPS by URL's?
Top
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: Default Deny Web Filtering

Wed May 25, 2011 6:24 am

No, since the host and path requested are only inside the SSL wrapper.
Top
Ishikawa
just joined
Topic Author
Posts: 4
Joined: Thu May 19, 2011 3:56 am

Re: Default Deny Web Filtering

Fri May 27, 2011 11:49 am

What about using SNI feature of SSL and TLS to find the hostname?
http://en.wikipedia.org/wiki/Server_Name_Indication

Untangle does this using SNI to find the hostname:
http://wiki.untangle.com/index.php?titl ... ldid=12879
Now uses SNI to filter HTTPS traffic by hostname
Also, DansGuardian does this. Not sure how.
http://dansguardian.org/?page=introduction
能够过滤https请求URL过滤.
Top

Who is online

Users browsing this forum:surekand 12 guests