NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Conax's avatar
Conax
Guide
Jul 05, 2021

Orbi not blocking sites in Keyword/Domain list

The original post is here: https://community.netgear.com/t5/Orbi/Orbi-not-blocking-sites-in-Keyword-Domain-list/td-p/1845336

Netgear has not replied to that post with a solution, but closed that post due to 'inactivity'. I think that's quite lame, so here's the new post.

 

So far we know the problem is that the 'Block Sites' functionality only blocks http (non-secured) sites that matches the keyword. Some people thought that it works for Edge but does not work for Chrome. Well, the reason for that behaviour is that when you enter an URL into Chrome, Chrome defaults it to a https URL. But Edge will default it to a http URL. Let's try this:

 

1. Configure your Orbi to block "twopalyergames.org".

2. Open Chrome, enter the url "twopalyergames.org". Orbi does not block it, and you can see that the site is secured.

3. Type the full http URL into the address field "http://twoplayergames.org". Now it is blocked by Orbi in Chrome.

4. Now open Edge, enter the url "twopalyergames.org". Orbi blocks it, and you can see that the site is NOT secured.

5. Type the full https URL into the address field "https://twoplayergames.org". Now it is not blocked by Orbi in Edge, and you can see the site is secured.

 

For sites that auto redirects from http to https, you will never be able to block it. For example, http://mylotto.co.nz.

 

Come on Netgear, we paid a fortune for your product, when are you going to release the firmware to fix this issue?

10 Replies

  • schumaku's avatar
    schumaku
    Guru - Experienced User

    Well, the "last" answer might be it's not possible at all - certainly not without dealing with some end point security.

     

    Netgear's current implementation does capture http traffic - alone this is useless nowadays (as explained several times now).

     

    Up to TLS 1.2, it might be possible to find the URL called in the initial handshake. For sites using TLS 1.3 this is no longer feasible.

     

    The last design approach would be capturing the plain text DNS for DNS queries ... what is easily circumvented when also using secured/encrypted DNS.

     

    Now read the first line again....

     

    Same limitation on advanced security appliances by the way.

    • Conax's avatar
      Conax
      Guide

      And I just found out, the free modem that came with Spark fiber can block https urls without issue. Does this mean the modem passes text url to the Orbi router for http traffic, but encrypted url for https traffic?

      • schumaku's avatar
        schumaku
        Guru - Experienced User

        Conax wrote:

        And I just found out, the free modem that came with Spark fiber can block https urls without issue.


        Don't know anything about this device implementation or the Spark service named Net Shield.

         

        As I said, the https connection is either <=TLS 1.2, or the device is filtering plain text DNS.  Both is technically feasible (hey I'm not Netgear, but they kow from where I'm coming from ....) so I can say the current Keyword Blocking feature is just j**k. Try using an encrypted DNS and you might find the computer does bypass....