USG110 - UTM Content Filter results not being logged?

Options
USG_User
USG_User Posts: 369  Master Member
First Anniversary 10 Comments Friend Collector First Answer
edited April 2021 in Security
Hi guys,

We experience the following issue with our USG110 @ V4.30(AAPH.1)ITS-WK51:

We've activated an UTM Content Filter and define a Content Profile where the 4 Content Filter Category Services are enabled. Within the Policy Control this Content Filter has been assigned to our web access rules.

Within the filter definition: While Security Threat Web Pages and Managed Web Pages are set to BLOCK, Unrated Web Pages and Category Server Unavailable are set to WARN only. But the LOG Checkbox behind each of the 4 Services are all enabled.

The filter is working so far. But only both WARN categories are being added to the log. Any blocked webpages are not being logged. Is it a bug or feature? ;)

Greetings
Joerg

Comments

  • bymusty
    bymusty Posts: 17  Freshman Member
    First Anniversary 10 Comments Nebula Gratitude Friend Collector
    Options
    Hi Usg user

    Although it is not selected as active, UTM logs must be enabled in Log settings. Utm will you log in and try again?
  • USG_User
    USG_User Posts: 369  Master Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi bymusty,

    I'm aware of this. The normal log is already activated. Nevertheless the log doesn't contain anything in this regard.


  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    First Anniversary Friend Collector First Answer First Comment
    Options
    @USG_User
    I think your Firmware is 4.25 not 4.30.....
    I tested it locally with firmware: V4.30(AAPH.0)ITS-WK06-r82206 and the message will be displayed on log page.


    I will private message the firmware to you for your testing.
    Charlie
  • USG_User
    USG_User Posts: 369  Master Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi Charlie,
    Thanks for your inexhaustible effort. This is a great help to the community.

    We've got a bugfixed v4.30 running, not a 4.25.



    First I have set all checkboxes in the Content Control as advised above. And surprise, all blocked websites are being logged now. Then I have unticked some checkboxes again to see, which one is responsible for the logging. But finally I have the same "checkbox state" than before, but the log is still working.


    The content filter report service is only for reporting our query results to the Zyxel server, and that's why not really necessary.



    Enable Safe Search is only for suppressing search results for some search machines. Not really important for the right working of the log.

    Insofar I didn't change any important things. Only ticking all checkboxes and subsequently unticking. But now it works.

    Thanks and greetings
    Joerg

Security Highlight