312
Controlling traffic at the security gateway
Blocking inappropriate content with content filtering
5
In the Available list, select the content category that you want to move into the Categories to block
list, and click the right-arrow >>
button.
Users are not permitted to access URLs contained in the content categories that are in the Included
Categories list.
6
Check
Enable Dynamic Document Review
.
7
Click
OK
.
8
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
9
After creating the content profile, you can use it to restrict content in a rule.
Related information
For further information related to this topic, see the following:
■
■
“Content Filtering Profile Properties—General tab”
■
“Adding content filtering protection to a rule”
■
“Understanding and using licenses”
■
“Configuring and running LiveUpdate”
What happens when you deny a content category
When you create a content profile, you place the content categories to which you want to deny access
in the Included Categories (deny) list, based on the acceptable-use policies of your organization.
Content categories in the deny list override categories that are not in the deny list. For example, if you
place the same URL in two different content categories, and one category is in the deny list and the
other is not, users are blocked from accessing the site. This is because the URL is in at least one content
category in the deny list.
When a request is made for a URL that is contained in a deny list, the request is blocked. An Access
Denied page is returned.
What happens when a content category is not denied
When a content category is not in the deny list, it is not consulted when the security gateway checks
lists for which URLs to block. Users can access URLs in content categories that are not in the deny list,
and the text is subject to screening by DDR using the active dictionaries of categories that are in the
deny list.
Modifying the contents of a content category
You can add URLs to a content category. Because Internet sites change regularly and because the
Internet is growing rapidly with hundreds of new sites being added daily, it is easy to find sites that
have not yet been categorized into an appropriate predefined list. If you find such sites, you can add
them to your content categories list. Once you add a URL to a content category, access to the URL is
allowed or denied based on the state of that content category.
URLs that are added manually or that are modified are stored in a local database that is separate from
the predefined URL content category database that is supplied by Symantec. When a URL request is
made, both databases are parsed. Entries in both databases have the same level of precedence. If an
entry exists in both databases, but is assigned to different categories in each, users are denied access to
the URL if any of the categories are in the deny list. Categories that are not denied are implicitly
allowed.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...