304
Controlling traffic at the security gateway
Blocking inappropriate content with content filtering
Related information
For further information related to this topic, see the following:
■
“Content Filtering—Advanced Restrictions tab”
■
“Content Filtering Advanced Restrictions tab—MIME Type dialog box”
■
“Adding content filtering protection to a rule”
Filtering by file extension
You can create an allow or deny list (but not both) to control access to files with certain extensions for
HTTP traffic. This provides a way to allow or deny specific file types. For example, you can allow users
to download text or HTML files, but not binary executables. This feature is enabled when you check
Apply file extension restriction in the HTTP parameters for a rule that contains HTTP.
Files with no extension are assumed by default to have .html extensions.
Prerequisites
None.
Filter by file extension
To fIlter traffic based on a specific file extension, you must do the following:
■
Specify the file extension and whether it is allowed or denied.
■
Create a rule and apply the file extension restriction.
To filter by file extension
1
In the SGMI, in the left pane, under Policy, click
Content Filtering
.
2
In the right pane, on the Advance Restrictions tab, under File Extensions, in the Available list,
select the file extension you want to restrict and click the right-arrow > button to add it to the
Selected list.
3
To remove a file extension from the Selected list, highlight the entry, and then click the left-arrow <
button.
The entry is moved to the Available list.
4
To add new file extensions to the Available list, do the following:
■
Under the File Extensions Available list, click
Add
.
■
In the File Extension dialog box, in the File extension text box, type the file extension that you
want to add.
■
Click
OK
.
5
On the Advanced Restrictions tab, to delete a file extension from the Available list, highlight the
entry, and then click
Delete
.
6
To allow or deny the file extensions in the Selected list, below the list, select one of the following:
7
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Allow
Permits users to download only files with the file extensions in the Selected list.
Deny
Permits users to download all files regardless of extension except those in the Selected list.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...