Sonicwall : Bypassing content and application filtering

sonicwall

We have SonicWall installed in our networked that turned pretty much useless lately, regarding content filtering, after employees found a trick to bypass it and spread the word around.

Could you please recommend the common tricks used to bypass SonicWall rules and their countermeasures I should configure the SonicWall to, to block these holes to force the company internet access policy?

Best Answer

There will always be ways around content filters. My lists aren't extensive, but here are some items that should help cover most of your concerns.

  • Most common methods to bypass web filters is to use a web-based proxy website

Example:Logging into a free web proxy web service; this is a service that's provided by visiting a website that will mask your web browsing through their website

  • Some people bypass web filters through VPN, which encapsulates traffic and prevents your local web filter from viewing content/destination

Example: Logging into a VPN service from a service provider; since all traffic going through that service is going to be encrypted, no one will be able to tell what you're doing while connected to the service (so long as the traffic is going through the service)

Some methods you can employ are:

  • Forcing proxy servers through GPO

http://social.technet.microsoft.com/wiki/contents/articles/5156.how-to-force-proxy-settings-via-group-policy.aspx

  • Forcing proxy through DHCP, DNS and routing rules

http://smallbusiness.chron.com/set-up-dhcp-provide-proxy-server-50621.html

  • Using a 3rd party web filter solution (one that allows filtering by IP, domain names, and content)
Related Topic