NxFilter not Blocking

Skip to first unread message

Michael Patrick

Feb 16, 2016, 3:45:32 PM2/16/16
to NxFilter
I have integrated AD into NxFilter, however when I try to test using my own login to block facebook.com it does not work. The logs show it to be an anon-user with my IP navigating to Facebook.com. Could someone assist?

Dime I

Feb 16, 2016, 4:59:13 PM2/16/16
to NxFilter
Have you ran/installed nxlogon on your test computer?  All workstations need to have nxlogon run at startup/login for nxfilter to 'know' which specific user it's requesting.

Michael Patrick

Feb 16, 2016, 5:37:25 PM2/16/16
to NxFilter
I have and it is pointing to the IP address for the machine. It is now logging the username but still not blocking the website.


Feb 16, 2016, 8:49:52 PM2/16/16
to NxFilter
Several things to check,

1. Did you enable authentication on 'Config > Setup'?
  - I guess you did as you said you run NxLogon and see username in your log-view.

2. Do you use NxFilter as your only DNS server for your client system?

3. How did you block facebook.com? By whitelist with 'admin_block' option?

4. What do you get when you use 'nslookup facebook.com' against your NxFilter?

Michael Patrick

Feb 17, 2016, 8:24:08 AM2/17/16
to NxFilter
I did enable authentication, I do not use it as my only dns server just my primary, I blocked Facebook.com through the custom categories and added *.facebook.com 

Non-authoritative answer:
Name:    facebook.com

Michael Patrick

Feb 17, 2016, 8:25:39 AM2/17/16
to NxFilter
Also I added the policy to my user account for that category. Sorry forgot to mention that

Jinhee Lee

Feb 17, 2016, 8:46:18 AM2/17/16
to NxFilter
So your secondary dns works. Make it the only dns server.

Michael Patrick

Feb 17, 2016, 9:07:53 AM2/17/16
to NxFilter
Trying that knocked me off the internet completely, so that could be why this is not working. I tested blocking it in admin block through whitelist and that worked. Since we are talking about removing the secondary, once I get the NxFilter machine to work as a primary by itself can I re-add the seconday? We need a failover solution in case the primary goes down.


Feb 17, 2016, 9:46:43 AM2/17/16
to NxFilter
Have one more NxFilter as your secondary DNS server. We support even clustering. This is actually for more than you can expect from a free sulution. But some of our users even use 3 NxFilter clustered. Seemed like an overkill to me though.

Michael Patrick

Feb 17, 2016, 9:56:17 AM2/17/16
to NxFilter
So in order for it to work we cannot use a normal dns server as a secondary? They both have to be an NXfilter device?

Michael Patrick

Feb 17, 2016, 10:05:28 AM2/17/16
to NxFilter
So I have only the NXfilter set up as my DNS server, I am on the internet now but it still is not blocking. The way I have done it is created a test called Facebook which blocks *.facebook.com then a test policy and added my own user account to the policy and ensured the Facebook category was checked under the blocked domains. Cleared all my cache and flushed my dns. I am still able to browse to facebook.com.

Michael Patrick

Feb 17, 2016, 10:13:32 AM2/17/16
to NxFilter
A little more information. I am able to block websites globally so I believe it is the policy having the issue. I am just not sure where in the policy I am messing up

Michael Patrick

Feb 17, 2016, 10:21:40 AM2/17/16
to NxFilter
Sorry to keep posting updates, I am noticing more as I move forward. The log is showing me to still be in the default policy even though the user list shows me to be in the test policy.

Dime I

Feb 17, 2016, 10:31:01 AM2/17/16
to NxFilter
You should probably block connect.facebook.net too

Michael Patrick

Feb 17, 2016, 10:32:25 AM2/17/16
to NxFilter
Wouldn't *.facebook.com cover that since * is a wildcard?


Feb 17, 2016, 10:46:34 AM2/17/16
to NxFilter
On your list the policy being shown is your user policy. But on NxFilter group policy comes before user policy. To find out which policy your user actually fall it click 'TEST' button on user list.

Michael Patrick

Feb 17, 2016, 10:51:57 AM2/17/16
to NxFilter
I figured it out.. It is applying my user group policy instead of the user specific policy.. now to find out how to stop that.

Michael Patrick

Feb 17, 2016, 10:55:06 AM2/17/16
to NxFilter
Is there any way to stop the group policy from taking over or to stop the groups from importing through AD and only have the users import?

Dime I

Feb 17, 2016, 11:08:38 AM2/17/16
to NxFilter
No because the difference is .net and .com

Michael Patrick

Feb 17, 2016, 11:13:25 AM2/17/16
to NxFilter
Oh I didn't see the .net my mistake. Thanks!


Feb 17, 2016, 11:34:40 AM2/17/16
to NxFilter
If you don't want to import groups use 'exclude keywords'. And group policy comes before for your convenience as many people want to do everything on AD side. Once you figure out all the policies and groups and users then you just move one user to another group when you want to apply a different policy to the user.

Michael Patrick

Feb 17, 2016, 12:00:32 PM2/17/16
to NxFilter
That worked! thanks.
Reply all
Reply to author
0 new messages