In this article
This article covers how to diagnose and correct a site that is wrongly allowed under a Filtering Policy.
When websites are wrongly allowed, there are three possible areas of causation:
- A device issue. This is related to caching or DNS settings not being applied for the particular device
- A network issue. The location may be incorrectly configured in the DNSFilter dashboard or on the LAN network equipment. Refer to the Site Deployment Guide, Site Troubleshooting, and Transparent Proxying articles for details
- A policy issue. The appropriate categories may not be blocked, or may not be applied to the correct sites. Refer to the Policies article for details
Question 1: Is it only this device?
(If more than one device is affected, skip to the next question)
If only one device is having the problem, network equipment can be eliminated from the scope of troubleshooting. If there is only one device with the issue, the following checks help connect the device correctly.
-
Perform a MyIP test using the instructions in the Not Connected article. If performing an
nslookup myip.dnsfilter.com.does not return a successful query, the device is not pointed to DNSFilter for resolution. The adapter settings may be set to point to a different DNS server, which allows access to sites blocked in the policy. Change the network adapter settings to point to DNSFilter, either on the device itself or through another means - Perform a fresh block test. Due to browser caching, sites blocked in the policy may still display if they were viewed prior to being added to the Block list. Although the site is blocked on DNSFilter's end, the browser has stored the information locally and continues to display it. Add a new domain to the Block list, then attempt to access it in incognito mode to confirm the block is working correctly
Question 2: Is it only this policy?
If multiple devices on a given network are able to access a forbidden website, the problem lies in a site-wide configuration issue or a policy issue.
- Follow the steps in the Not Connected article to confirm the site is actively passing traffic to DNSFilter's servers. If the site is not passing traffic, follow the instructions in that article to connect all of the site's IPs to the dashboard
- Set up a category, such as Adult Content, to be blocked in the policy. Attempt to visit
adult.filterdns.netfrom an incognito-mode browser. A block notification or a notice that the adult category is not being blocked will display. If the category is blocked, the site is connected and referencing a policy. The issue likely lies with the particular website: many sites use more than one address, allowing access even when the main domain is blocked. Refer to the Pages Not Loading article to find all relevant domains for the site and add them to the Block list - If some sites are blocked and some are not, the most likely cause is that the wrong policy is applied to the wrong location. From the DNSFilter dashboard, navigate to Deployments and check whether the policy assignment is correct. For environments with multiple policy attributes (Users, Collections, Roaming Clients, and Sites), refer to the Troubleshoot Filtering Policies in complex environments article for a deeper walkthrough of checking policy priority and assignment
Comments
0 comments
Please sign in to leave a comment.