- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: Anonymizer filtering blocks access to Intuit /...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anonymizer filtering blocks access to Intuit / Quicken services :-(
I have an SMB customer on 730 box that is under subscription maint.
Everything has been fine for years. Last night or today something changed.
Client is small tax firm with only a couple of employees. They use Quicken/Intuit software to complete tax returns.
Quicken/Intuit is apparently routing traffic to akamaitechnologies.com owned sites and the 730 is blocking it.
An example IP is: a23-212-249-86.deploy.static.akamaitechnologies.com [23.212.249.86]
I have disabled Anonymizer URL filtering for the moment so tax returns can be prepared.
Very small company of trusted employees. I'm thinking there is no big risk of having the filter turned off...
but am looking for other opinions, or suggestions to tighten things up.
THANKS!
OldGeek
- Labels:
-
URL Filtering
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would block Anonymizer , because if users figured out how this works the rest of the policy you made can by bypassed via proxy.
Same for VPN's. If they run and are allowed to run VPN all traffic is encrypted and the policy you made is not usefull.
Second point, looks like there was a false positive. If I check the URL now it should be allowed.
Can be verified on: https://urlcat.checkpoint.com/urlcat/main.htm
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Lesley!
I did not know about the URL lookup feature ... silly old man that I am ... 🙄
It does appear to have been false positive! I'll tell him to "Try it now" 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The latest software for the 730 does not support SNI which is how we are able to categorize websites without full HTTPS Inspection.
That means sites will be categorized according to the site certificate CN only, which will often reflect a different site (e.g. Akamai) if a CDN or similar is used.
The only solution to this problem is to upgrade to newer hardware that supports newer software versions that support SNI...or use full HTTPS Inspection.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks PhoneBoy!
The 730 is more than a few years old.... I'll suggest the budget for a new device (when tax season is over 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would block Anonymizer , because if users figured out how this works the rest of the policy you made can by bypassed via proxy.
Same for VPN's. If they run and are allowed to run VPN all traffic is encrypted and the policy you made is not usefull.
Second point, looks like there was a false positive. If I check the URL now it should be allowed.
Can be verified on: https://urlcat.checkpoint.com/urlcat/main.htm
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Lesley!
I did not know about the URL lookup feature ... silly old man that I am ... 🙄
It does appear to have been false positive! I'll tell him to "Try it now" 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which version & build of firmware is used on this 700, these will be EOL in October 2024.
Further to the limitations called out above note there were some recent issues with categorisation which I believe were resolved since.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Chris!
I'm traveling today and don't have the details with me, but the unit is under service contract.
We will budget for replacement over the summer, once the "thrill" of tax season is over!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe this is related to the mass false positive that occurred around Sun~Mon last week.
The IPs categorized as Anonymizer should be mostly fixed by now. Do you still experience the issue?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Tom - will be testing this soon!
