SD-WAN

 View Only
last person joined: 2 days ago 

Forum to discuss HPE Aruba EdgeConnect SD-WAN and SD-Branch solutions. This includes SD-WAN Orchestration WAN edge network functions - routing, security, zone-based firewall, segmentation and WAN optimization, micro-branch solutions, best practics, and third-party integrations. All things SD-WAN!
Expand all | Collapse all

WebCC filtering in VPNC's LAN port

This thread has been viewed 22 times
  • 1.  WebCC filtering in VPNC's LAN port

    Posted Jun 18, 2021 10:31 PM
    Hi all, I have a deployment in which a VPNC is used for terminating IPSec tunnels from other locations, but it also works as the main router and one of its ports is configured as WAN with a public IP address.

    On the other side, there are many LAN ports with different VLAN and I want to restrict user traffic to streaming, social networking, etc. I already turned on DPI and WebCC in the VPNC and made a policy restricting web categories streaming and social networking.

    After doing that, I applied this policy to a new trusted LAN interface (new VLAN also) that I setup for testing purposes, but test clients connected through an unnamaged switch to the VPNC's test LAN interface are still able to open YouTube, Facebook, etc.

    What do you think I could be missing here?

    Regards.

    ------------------------------
    Abdel Castro Perpuli
    ------------------------------


  • 2.  RE: WebCC filtering in VPNC's LAN port

    EMPLOYEE
    Posted Jun 19, 2021 08:39 PM
    when you want to apply any policies to vlan/interface, it is required that to be untrusted.
    this applies to all VPNC/BGWs.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 3.  RE: WebCC filtering in VPNC's LAN port

    Posted Jun 19, 2021 09:54 PM
    But Central says that Firewall Policies are applied in trusted interfaces:

    trusted
    Actually a policy is currently applied to this test interface and a rule set for restricting a domain name works (although another different one does not).


    ------------------------------
    Abdel Castro Perpuli
    ------------------------------



  • 4.  RE: WebCC filtering in VPNC's LAN port

    EMPLOYEE
    Posted Jun 19, 2021 10:52 PM
    i thought you were after applying user role policies.
    in either case you need to check if the traffic is matching your interface policies.
    check with this
    show web-cc stat
    show datapath session web-cc


    also it is good practice to enable " Drop packets during webcc miss" check box

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 5.  RE: WebCC filtering in VPNC's LAN port

    Posted Jun 21, 2021 09:04 AM
    WebCC commands' output makes me think everything is running well with it.

    I rearranged the rules but I'm no sure if that will work:

    rules


    A question, wouldn't "Drop packets during webcc miss" drop unclassified traffic? There is traffic for internal applications that it is not classified and must not me dropped.

    ------------------------------
    Abdel Castro Perpuli
    ------------------------------



  • 6.  RE: WebCC filtering in VPNC's LAN port

    EMPLOYEE
    Posted Jun 21, 2021 07:28 PM
    i think it is best to open a TAC case.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------