Dell SonicWALL Secure Mobile Access 8.5
Administration Guide
324
2 Click
Enable Remediation
. Denied users might not be able to access the appliance without CAPTCHA-
based remediation. Remediation can be enforced separately for the IPs defined by your Geo IP Policy,
Botnet Filter Policy, and/or Botnet Database. Select additional options as needed.
3 In the
Max allowed time for CAPTCHA entries (s)
field, select the maximum amount of time (in
seconds) that the user has to complete Remediation. The minimum/maximum range is 30-300 seconds,
with default value for this field being 60 seconds.
4 In the
Allowed/Blocked duration after CAPTCHA validation (m)
field, select the duration of time (in
minutes) that the user is allowed/blocked after completing the CAPTCHA validation. The minimum value
is 5 minutes and the maximum is 30, with the default value being 15 minutes.
Access Policies
The
Geo IP & Botnet Filter > Policies
page is used to view, add, edit, and delete Geo IP and Botnet Filter
access policies. Up to a total of 64 Geo IP and Botnet Filter access policies can be created.
Each policy is automatically assigned a different priority with 1 being the highest priority. A policy’s priority
determines the order of enforcement that is identified by the order they are listed on the Settings page.
•
Botnet Filter policies have a higher priority than Geo IP policies. Geo IP policies are prioritized by the
time they were created with those created first having the higher priority.
•
Botnet Filter policies defined for a single IP address have a higher priority than Botnet Filter policies
defined for a subnet, and each type is then prioritized based on the time they were created with those
created first having the higher priority.
•
Custom created polices are enforced first, which means if an IP address is listed in the SonicWALL Botnet
Filter database, but admin defines an allow policy for this IP, then access from this IP is allowed.
A policy can be modified by clicking the
button, but a policy name cannot be modified.
A policy can be deleted by clicking the
button.
To create a new access policy, click the
Add policy...
button. Two types of policies can be added:
• Geo IP Policy
tab — A Geo IP policy allows or denies traffic from specified countries. Enter a
Policy
Name
, then select the
Countries
you want to allow or deny. You can sort countries by continent, just
click the drop-down and select the desired continent, all the countries within that continent displays in
the
Apply Policy To
list. You can also select countries directly from the map.
The map displays selected/deselected countries by color. The deselected countries display gray, while
the selected countries display in color. Mouse over a country in the
Apply Policy To
list and the