OPNsense Forum

English Forums => Zenarmor (Sensei) => Topic started by: Seimus on January 30, 2025, 07:45:02 PM

Title: ZA 1.18.5 | New category "Google Streaming via Quick" breaks TCP based traffic
Post by: Seimus on January 30, 2025, 07:45:02 PM
Hello all,

ZA 1.18.5 Introduced new App control category called Google Streaming via Quick", Which I believe was created to split general QUIC with specific QUIC for Google services. However;

ZenArmor wrongly identifies TCP based traffic as Google Streaming via Quic and as App protocol UDP which results in blocking TCP based connections for Google services if the "Google Streaming via Quick" is set to block in policies.

I did open a ticket with ZA about this.

Regards,
S.
Title: Re: ZA 1.18.5 | New category "Google Streaming via Quick" breaks TCP based traffic
Post by: sy on January 31, 2025, 12:04:48 AM
Hi,

This application features a collection of Google IPs primarily utilized for streaming, although it appears that Google employs them for various other services too. An update will be provided with the next database release.
Title: Re: ZA 1.18.5 | New category "Google Streaming via Quick" breaks TCP based traffic
Post by: Seimus on January 31, 2025, 12:11:54 AM
Hello Sy,

That specific category is for "Google Streaming via Quick", which I understood should only match UDP + Google IP range. Currently its matching both UDP as well TCP on various ports, which is wrong and causing a lot of problems.

But glad to hear it will be fixed.

Regards,
S.
Title: Re: ZA 1.18.5 | New category "Google Streaming via Quick" breaks TCP based traffic
Post by: sy on February 08, 2025, 08:09:12 AM
Hi,

This update will be included in the 1.18.6 version, which is scheduled for next week. We appreciate your cooperation and patience.


Best regards