Hello people.
As I have no complains with the IPF in general, the filtering bussines is a total madness. There’s no way to get some unified results in different machines to be able to draw some sane conclusions.
All my hosts are DHCP, none fixed. The DNS is configured to force all traffic through firewall - following wiki. I have Talos and emerging threats lists activated with only the rules they come with selected. For IP address lists I selected just bogons, both emerging lists and I guess nothing more. The web proxy non-transparent on both green and blue - configured on hosts machines not through DHCP wpad. For URL filter only ads, malware, phising and stalkware.
Now… what’s happening is maddening and hilarious in the same time. Depending on browser brave/ firefox and hosts the results are not the same. For instance I can access youtube on an android phone but only on firefox (and not on brave). On an apple machine yt is not reachable at all - firefox or brave.
Yt is one example, there’s much more - various benign media portals, blogs, tech sites etc.
I have an appletv (on blue) in which wifi works but only locally - it is able to stream from a media server (on green) but no internet whatsoever. No proxy configured on that particular device, but the amount of traffic that appears as forwardfw in firewall log for this IP is absolutely insane - mostly 443 apple/ amazon IPs (different topic - though I would like to filter some of it).
The main question being… where/ how can I check the blocked traffic to have at least some indication of who is blocking what to obtain a better understanding on how the filtering works and why the filtering is so randomly from a host/browser to another… and finally to be able to fine tune a bit the lists. For instance the SARG/ Proxy reports shows some denied traffic for the apple machine IP (not appleTV), but youtube is not there (at all!). The proxy logs shows all traffic, without any specifications. The only log that speaks clearly is IPS log viewer - it names the lists that deny the hit and the reason for which is doing so.
Could anybody enlighten me a bit? Thanks.