How to block Google Hangouts on Desktop and mobile devices using App rules
10/14/2021 27 People found this article helpful 482,445 Views
Description
This article describes how to block Google Hangouts on Desktop and mobile devices using App rules
Resolution
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Note:
- This solution blocks DNS requests / responses only. If Google Hangouts is open before enabling this rule, it might allow access. However, when attempting to open afresh, it will be blocked.
- This solution will not work if the DNS requests and / or responses do not traverse the SonicWall. For instance, if the DNS server of devices is behind the SonicWall and the DNS server has cached the IP addresses of Google Hangouts, such queries may not traverse the SonicWall and therefore will not be blocked by SonicWall.
Procedure:
Create Match Object
- Login to the SonicWall Management GUI
- Click Manage in the top navigation menu
- Navigate to the Objects | Match Objects page
- Click on Add and select Match Objects to open the Add/Edit Match Object window.
- Enter a name for this object under Object Name
- Set Match Object Type to Custom Object
- Set Input Representation as Hexadecimal
- Under Content, enter the following hex strings:
- 056d74616c6b06676f6f676c6503636f6d00
Note: This will block DNS queries / responses for mtalk.google.com - 7777770a676f6f676c656170697303636f6d
Note: This will block DNS queries / responses for www.googleapis.com
- Click on Add
- Click on OK
Create App Rule :
- Navigate to the Rules | Application Control page.
- Click on the Add button to open the Edit App Control Policy window.
- Enter the following information and click on OK.
Note: You could lock it down further by Zone. For example,
- Set Connection Side to Server Side or Both
- Click on Advanced under Direction
- Set From to Any and To to WLAN (Any in case the server is internal)
This will block DNS response from a server on the WAN or LAN.
- To enable App Rules, Click on the Settings icon in the top of the same page Rules | Application Control
- Check the box Enable App Rules and Click on Accept
Testing:
In Chrome browsers, try to open the Hangouts app and it will fail. On mobile devices, the Hangouts app will open but will not be able to send messages.
The following message will be logged in the SonicWall under Investigate | Event Logs
Resolution for SonicOS 6.2 and Below
The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.
Note:
- This solution blocks DNS requests / responses only. If Google Hangouts is open before enabling this rule, it might allow access. However, when attempting to open afresh, it will be blocked.
- This solution will not work if the DNS requests and / or responses do not traverse the SonicWall. For instance, if the DNS server of devices is behind the SonicWall and the DNS server has cached the IP addresses of Google Hangouts, such queries may not traverse the SonicWall and therefore will not be blocked by SonicWall.
Procedure:
Create Match Object
- Login to the SonicWall Management GUI
- Navigate to the Firewall | Match Objects page ( In older SonicOS firmware this page would be under Application Firewall | Match Objects)
- Click on Add New Match Object to open the Add/Edit Match Object window.
- Enter a name for this object under Object Name
- Set Match Object Type to Custom Object
- Set Input Representation as Hexadecimal
- Under Content, enter the following hex strings:
- 056d74616c6b06676f6f676c6503636f6d00
Note: This will block DNS queries / responses for mtalk.google.com - 7777770a676f6f676c656170697303636f6d
Note: This will block DNS queries / responses for www.googleapis.com
- Click on Add
- Click on OK
Create App Rule
- Navigate to the Firewall | App Rules page.
- Click on the Add New Policy button to open the Edit App Control Policy window.
- Enter the following information and click on OK.
Note: You could lock it down further by Zone. For example,
- Set Connection Side to Server Side or Both
- Click on Advanced under Direction
- Set From to Any and To to WLAN (Any in case the server is internal)
This will block DNS response from a server on the WAN or LAN.
- Enable the check-box Enable App Rules.
Testing:
In Chrome browsers, try to open the Hangouts app and it will fail. On mobile devices, the Hangouts app will open but will not be able to send messages.
The following message will be logged in the SonicWall under Log | View
Related Articles
Categories
Was This Article Helpful?
YESNO