-
FQDN blocked site exception - not able to create
I'm not sure if this is the right category in which to post, so please direct me elsewhere if that's appropriate. I am trying to add a new Blocked Site Exception based on the FQDN, and no matter what I try to add, I get a message that "The domain name is invalid." I'm on the current OS, 12.12.1, and I even restarted the…
-
Safe Search
12.4 Does enabling Enforce Safe Search no longer work for Google? I can search images.google.com for anything and all kinds of NSFW images appear, but for Bing, Yahoo, and YouTube I get rejected and am unable to turn Safe Search off in the browser. Anyone else notice this? * Doug
-
is NAT dynamic and/or 1-to-1 needed for a HTTP proxy rule ? M295
I have a HTTP-proxy rule on port 80 and I am wondering if I need the NAT enabled in the Advanced → NAT part of the configuration I have Win PC on internal lan that seldom need to connect to HTTP web on outside/public web My understanding is that the proxy will connect to the outside web using the public IP of the M295, so,…
-
HTTP Request and Authorization rules
Hello. The defaults for Authorization in HTTP Proxy settings includes: Basic, Digest, NTLM and Passport1.4. All other authorization headers are stripped. I started looking at the HTTP Request Authorization list on a freshly installed WG when I couldn't access onedrive.live.com/login page on a computer with HTTPS inspection…
-
Windows 11 HTTPS traffic to tse1.mm.bing.net seen in WatchGuard logs
Hello, I am analyzing some HTTPS traffic detected by a WatchGuard firewall from a few Windows 11 PCs. In the logs I can see allowed connections to 150.171.27.10 and 150.171.28.10, with: sni="tse1.mm.bing.net" cn="*.mm.bing.net" traffic identified as SSL/TLS The traffic starts at the same time from multiple Windows 11 hosts…
-
Citrix Connection To State Gets Error
Hello all, I am very confused on this. Got a new M295 Firebox and advanced security. Without the advanced secruity we are able to get to the Montana Website through their citrix connection. Now that we put advanced security on the M295 firebox, when we try to connect to the Montana Website through their Citrix, we sign on…
-
Website blocked, but can't figure out why
Hi I have a little situation here. my teammate want to acces a website from a partner to byu hardware, it's a new partner, and thei website seems to be blocked by our proxy. But i can't figure out why On traffic, here's what i get : 2026-02-20 10:51:13 Member2 Allow 10.0.1.16 -removed- http/tcp 60783 80 Reseau local…
-
Unable to block Facebook
Hello, I have configured SSO in Ad and I can correctly see the user connecting, but the proxy rule (and/or Application Block) to block Facebook is ignored. I have obviously moved the rule to the top, but nothing changes. M390 release 12.11.7
-
Bestpractice for a RDGatway deployment
Hi everyone, I'd like to protect an RD Gateway server using an incoming HTTPS server content action to better defend against brute-force attacks, for example, with IPS. Unfortunately, my current setup isn't working. The certificate is imported into WatchGuard and assigned to the content action. Is there anything I need to…
-
ChatGPT suddenly slow/can't connect
since a couple of week, some of our users, that used Chatgpt, can't. (chatgpt.com) i don't remeber changing something in our proxy filtering (maybe our DSI, but he would advertise us in this case) when i check the traffic logs, i get this deny: 2025-12-10 15:44:23 Member2 Deny <clientIP> 172.64.155.209 https/tcp 53088 443…