Policy Effect on Edge but Not Chrome.

Newbie384936 Lv1Posted Oct-28-2025 12:49

Hi All,

After Policy done created it only works on edge but on chrome it's like some website blocked but some still able to access.

Any ideas?

By solving this question, you may help 955 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

net_specialist Lv1Posted Nov-17-2025 14:58
  
This issue—policy working on Edge but inconsistent on Chrome—is commonly linked to how Sangfor IAG handles URL filtering, application control, and SSL inspection across different browsers. Here are the main causes and fixes:

✅ Likely Causes


Policy Action Misconfiguration

If the policy is set to Allow instead of Deny in the Content Security module, it only detects but does not block. Ensure the action is Deny for blocking. [community....angfor.com]



Domain Handling Differences

Chrome and Edge resolve DNS and handle QUIC differently. If QUIC (UDP 443) is enabled, Chrome may bypass HTTP/HTTPS filtering. [knowledgeb...angfor.com]



SSL Inspection / Certificate Issues

Chrome enforces stricter certificate validation. If the Sangfor root certificate is not installed on endpoints, HTTPS filtering may fail partially. [community....angfor.com]



Browser-Specific Features

Chrome uses Encrypted ClientHello (ECH) and TLS 1.3 by default, which can interfere with older Sangfor versions. Disabling ECH or upgrading IAG firmware resolves this.


Troubleshooting Steps


Check Policy Settings

Go to Policies > Network Security > Policies and confirm:

Action = Deny
Correct source/destination zones and IPs.
Domain names added properly in Application Control (wildcards supported in newer versions).





Disable QUIC on Chrome

In Chrome, visit chrome://flags, search for QUIC, and set it to Disabled.
This forces traffic over TCP 443, allowing Sangfor to inspect it.



Install Sangfor Root SSL Certificate

Download from IAG > Online Activities > Advanced > SSL Certificate.
Deploy to all endpoints (Windows Trusted Root CA store).



Handle TLS/ECH

In Chrome, disable Encrypted ClientHello via chrome://flags.
If possible, upgrade IAG to 12.0.62 / 13.x or apply Sangfor SP patch for TLS 1.3 compatibility.



Clear Browser Cache

After policy changes, clear Chrome cache and restart the browser.


✅ Best Practice

Keep Application Signature & URL Database updated.
Enable Log Event in policies to verify enforcement.
For HTTPS filtering, always deploy the Sangfor certificate and disable QUIC.
Newbie767164 Lv1Posted Nov-11-2025 17:06
  
It's possible that a policy or extension setting is conflicting in Chrome — try clearing your cache or checking your site permissions first.
https://knowledgebase.sangfor.co ... 2articleType%22%3A1,%22articleId%22%3A%225e106bbcf8e54d36b817539acc762572%22,%22keyword%22%3A%22%22%7D<a href="https://fnfmods.io/">fnf mods</a>
Newbie517762 Lv5Posted Oct-30-2025 13:59
  
HiHi,


The issue where your firewall policy affects Microsoft Edge but not Chrome while using the QUIC protocol is quite common. Please try to block the QUIC protocol using the link below for your reference:
https://knowledgebase.sangfor.com/detailPage?articleData=%7B%22articleType%22%3A1,%22articleId%22%3A%225e106bbcf8e54d36b817539acc762572%22,%22keyword%22%3A%22%22%7D
CloudZero Lv1Posted Oct-30-2025 10:13
  
I have created:

Application control:
1. Policy - Denied Website (Blocked selected website)
- Src (Local LAN/VLAN), Dst (ISP/WAN/PPPOE)
- Src Zone (test)(Authenticate by Users/Group)
2. Policy - Allow Website (Allow website other than Blocked one)
- Src (Local LAN/VLAN), Dst (ISP/WAN/PPPOE)
- Src Zone (test)(Authenticate by Users/Group)

NGAF PLATFORM
VER. 8.0.47
MODEL: M4500-F-I


Seems like my firewall no option for domain name due to version.
Do I need to Create a Policy under Network Security?
No Policy under Network Security created for the Group(test) yet.

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Sangfor Jojo Lv5Posted Oct-30-2025 08:53
  
It may be related to how the URL filtering or application control policies are configured.

To address this, you can consider the following:

1. Ensure that the policy action in the content security module is set to "deny" to block access to specific websites. The "allow" action only detects without blocking, while "deny" detects and blocks access.

2. If you are using URL access policies, note that URL filtering is based on the target IP resolved by DNS and the HOST field of the server being accessed. Blocking external network access to internal servers using URL filter is not recommended. Instead, use application control policies to restrict access by source and destination zones, IPs, and ports.

3. Check if the domain names are properly added in the application control policy. The application control supports domain name-based blocking with wildcard support in certain versions (e.g., 8.0.59 - 8.0.95). Make sure the domain names are correctly configured and the policy is applied.

4. Verify that the routing and DNS configurations are correct, and test connectivity to internet websites to ensure no network issues affect policy enforcement.

5. If you want to restrict internal users from accessing specific external websites temporarily, you can implement this through application control policies or URL filters with custom URL categories and security policy templates.

By reviewing and adjusting these configurations, you can improve the consistency of website blocking across different browsers like Edge and Chrome.
For more details, please refer to:




Note: The above solutions are provided by Sangfor chatbot Solvia. If you want to follow up the further solution, please visit the page: https://community.sangfor.com/plugin.php?id=common_plug:robotList

I Can Help:

Change

Moderator on This Board

43
6
2

Started Topics

Followers

Follow

1
148
3

Started Topics

Followers

Follow

909
182
94

Started Topics

Followers

Follow

Trending Topics

Board Leaders