Web Filtering configuration (Mobile Threat Defense policy for iOS)
Restriction
This configuration only applies to supervised devices.
The Web Filtering configuration lets you manage the Web Filtering feature of Sophos Intercept X for Mobile. Web Filtering protects users from accessing malicious, undesirable or illegal web content.
Web Filtering blocks a website when the user opens it in Safari or another web browser and also when an app connects to it.
Warning
Web Filtering uses the Sophos website classification service https://4.sophosxl.net/lookup. If Web Filtering can’t connect to this service, it blocks all websites.
Tip
The Sophos website Web Security & Control Tests provides example pages to test your Web Filtering configuration and additional information about each category. Although some of these pages are classified as potentially offensive or dangerous, the content is harmless in all cases.
When you turn on Web Filtering, Sophos Mobile always blocks web pages categorized as highly objectionable criminal activity, such as child pornography. To prevent others from accessing these pages, Sophos Mobile masks the URLs in logs, events, and reports.
Settings
| Setting | Description |
|---|---|
| Filter malicious websites | Select whether users and apps can access websites with malicious content. |
| Create events | When users or apps try to open a filtered website, Sophos Mobile creates an event, which you can see on the device’s details page. You can select whether Sophos Mobile creates events only when a site is blocked or also for sites that produce a warning. |
| Filter websites by category | Select whether users and apps can access types of websites. Websites are categorized based on data from SophosLabs. The data is updated constantly. |
| Website exceptions | Configure exceptions to the category filters:
|
Website exceptions
Warning
Web Filtering applies to all web traffic, including traffic from third-party apps, system apps, and external resources that a website loads, such as fonts. Therefore, be careful when blocking domains, especially with wildcard entries. Blocking a domain that an app or website depends on can prevent the app from working properly or cause the website to load incorrectly.
In Allowed domains and Blocked domains, enter one item per line, without a separator. Use one of the following formats:
- IPv4 or IPv6 address
- IPv4 or IPv6 subnet
- Domain
- Wildcard domain
Usage notes
- The wildcard
*must be the leading character. - In Blocked domains, a single wildcard
*blocks all websites. - Don't include protocol prefixes such as
https://orchrome://.
Examples
The following examples show valid entries for Allowed domains and Blocked domains.
203.0.113.02001:db8:85a3:0:0:8a2e:370:7334203.0.113.0/242001:db8::/32www.example.com*.example.com*example.combookmarks(instead ofchrome://bookmarks)
Filtering logic
When Web Filtering evaluates whether a website must be allowed or blocked, the allow list takes precedence over the block list, and policy-defined lists take precedence over user-defined lists.
Filtering rules are applied in the following sequence:
- If the website is included in Allowed domains, it is allowed.
- If the website is included in Blocked domains, it is blocked.
- If the user has added the website to the allow list, it is allowed.
- If the user has added the website to the block list, it is blocked.
- If the website belongs to a category that’s forbidden, it’s blocked.