Sunday, November 21, 2010

Re: Security hole in your school filters

We don't block FB, but to answer your question...

You can block TLS or SSL traffic to any site with a decent firewall that can
preform DPI. In sonicwall this can be done by creating a custom application
object for, https// etc

The only drawback, which for us was outweighted the humongous costs DPI-SSL
service module, is that users will not get standard content filtering
message when they try to use SSL to bypass the filter -- HTTPS traffic to
that site will be simply dropped and their browser simply display a blank
page or an error (in Firefox) that "Connection was ropped".

Andrei Henriksan
St. Gregory College Preparatory School
Tucson, AZ

[ For info on ISED-L see ]
Submissions to ISED-L are released under a creative commons, attribution, non-commercial, share-alike license.
RSS Feed,