
4.2.5.1 Using the Local Site List Editor
1. On the Configuration > Group Policy > Local Site List page, click Add Site.
2. In the Specify the site to add text box, enter the URL, domain, top-level domain (TLD), IP
address, or
range that you want to add.
To add multiple entries by entering one per line, click Enter multiple sites to expand the
Specify the site to add text box. Click Enter single site to reduce it to single line size. When
URLs are added, the protocol is stripped from the URL. So, to the Web Appliance,
http://example.com
is the same as
ftp://example.com
. Note that:
■
A TLD entry should begin with a '.' (for example '.edu').
■
If you enter a domain or top-level domain (TLD) with a single subdomain level, any additional
subdomain levels will also be filtered. For example, an entry such as
example.com
will
also filter
subdomain.example.com
and
sub.subdomain.example.com
.
■
If your entry includes a domain and at least one level of subdomains, no additional
subdomains will be filtered. For example, an entry such as
subdomain.example.com
will not result in the filtering of other subdomains of
example.com
, including
other.
example.com
or
sub.subdomain.example.com
.
Note: Some TLDs are known as second-level domains. These are similar to a subdomain
and TLD. For instance,
.co.uk
is a second-level TLD that is distinct from
.uk
. In the
above, if
.example.com
was a second-level TLD, the other entries would be filtered.
■
You can simultaneously create different rules for TLDs and subdomains. For instance, if a
country had a TLD of
.zz
, you could block all sites by blocking the
.zz
top level domain
and then selectively allow specific sites such as
example.zz
.
■
You can add the URL of an HTTPS service that uses a non-standard port (other than port
443), which extends Web Appliance filtering support to that URL. We suggest that you set
such sites as Low Risk.
Important: The Web Appliance will interpret any dotted quad followed by a slash and a number
less than 33 as a CIDR range. This creates the possibility that a URL entered as an IP address
followed by a numbered directory from 0 to 32 would be improperly treated as a CIDR range.
For example,
http://192.168.3.4/6
, where '/6' is a directory, would be interpreted as a
CIDR range. To avoid this possibility, always enter URLs to numbered directories using fully
qualified domain names rather than IP addresses.
3. On the Modify the site properties panel, do one or more of the following:
Important: You must choose at least one of the following three options to create a new local
site list entry.
■
From the Tag editable drop-down list, either enter the name of a new tag that you want to
create in the text box, or click the adjacent down arrow icon to choose an existing tag from
the drop-down list.
Tags allow you to set policy rules more simply and flexibly than is possible by using other
policy features. Tags can be created in two places, this Local Site List Editor and the
Configuration > Group Policy > Additional Policy page. In the Additional Policy wizard,
you can set what action is taken in response to a tag. In this, the Local Site List Editor
Sophos Web Appliance | Configuration | 99