Newbe question about blocked/allowed streams

Comments

7 comments

  • Avatar
    Firewalla

    When did you first block Instagram? Was it close to 11:25AM? 

    0
    Comment actions Permalink
  • Avatar
    Anakin Skywalker

    I have "Social Blocking" enabled for all devices across the board, so my understanding is that it should always be blocked.  My daughter might be trying to access it on her Kindle (hence the blocked flows), but I am confused as to the one that is allowed.  The screenshot I sent was just a sample (I wanted to get both the blocked and allowed on the same screen for posting).  The DNS instances (like the one at 11:26 AM) are always blocked, and it's only the IP instances that are inconsistent.  I am really not trying to be dense..... it just comes naturally....:)

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Is social blocking the only rule you have? You said you allowed something, do you have another rule deal with Instagram? (paste all you can here, so we can take a look)

    1
    Comment actions Permalink
  • Avatar
    Anakin Skywalker

    Hi,

    I have several other things blocked such as porn, gambling, family protect, etc (all global).  I do have an explicit device-level rule allowing "Social," but that is specific to another device (my wife's Kindle, but she only uses Facebook).  Below I took several additional screenshots of that rule as well as the "allowed" instagram.  Most of the "allowed" instagram flows show a duration of 0s, but I found one that lasted 3 minutes (and I have seen one that lasted over 15 minutes, but I could not find that one).

    I'm also not sure what would be uploaded via UDP.  Also, I found an instance for Facebook with the same thing (which makes sense, since Facebook owns Instagram).  Finally, the last screenshot is of the domains listed under "All Social Sites," which shows both sites:

    Please let me know what other screen shots I can provide, and thanks for looking into this!

     

    0
    Comment actions Permalink
  • Avatar
    Anakin Skywalker

    Well, for giggles and grins I applied a device-level app block for instagram (since that is what we are looking at), and the results were even more confusing (showing that I have no idea what I am looking at).  The block was applied on the device page using the apps menu.  After doing so, I can no longer find the "i.instgram.com" listing under flows (allowed or blocked).  Even weirder is the fact that the flows blocked counter under the global social rule reads 33k, while the counter in the device-level block sows 44k….?!?  Since the device-level block is specific to my daughter’s Kindle, and the global is over all devices (and is for all social sites, not just instagram), shouldn’t the global have a higher count?  I have posed more screenshots below… Thanks again!

    P.S. My device (Gold) is under a different account than the one I used here.  The signin to Zendesk would not recognize the account I purchased the box through.   

    0
    Comment actions Permalink
  • Avatar
    Support

    Hi Anakin,

    There're a few things to note here:

    1. You saw i.instagram[.]com allowed and then being blocked because Firewalla needs a short period of time to learn what a domain/IP is, and if it matches any rule on box. The block/allow is not 100% strict but it should have very little impact, as modern app/website requires multiple connections to work. web.facebook[.]com is probably the same thing.
    2. You can't find certain domain in the flow history because some IPs are bond to multiple domains, and Firewalla only shows the latest domain that it sees.
    3. One network flow hits only one rule, either block or allow. Rules have different priorities, if a higher priority rule is hit, no other will.
    1
    Comment actions Permalink
  • Avatar
    Anakin Skywalker

    Thank you so much for looking into this, and explaining what I was looking at.  Obviously, I have a great deal to learn about my new toy, but that is part of the fun!  Thanks again for your patience...:)

    0
    Comment actions Permalink

Please sign in to leave a comment.