306
Controlling traffic at the security gateway
Blocking inappropriate content with content filtering
Filtering by subject matter
To provide content enforcement based on subject matter, you can create content profiles that specify
certain types of content for which access should be denied. You can create any number of content
profiles with different levels of content filtering and apply the appropriate content profile when you
configure a rule that contains HTTP. By specifying a content profile in a rule, you restrict access to
selected Web content for those users to which the rule applies.
To provide comprehensive filtering of Web content based on subject matter, the security gateway uses
a combination of the following:
You must have a valid Content Security license to enable the content categories and DDR. A valid
Content Security subscription license lets you receive updated DDR and content category definitions
through LiveUpdate.
Related information
For further information related to this topic, see the following:
■
■
“About Dynamic Document Review (DDR)”
■
“Understanding and using licenses”
■
“Configuring and running LiveUpdate”
About content categories
The security gateway uses content categories to determine whether access to specific URLs should be
denied. Predefined content categories are included with the software. You can use these categories or
create local modifications of the categories to fit your specific needs.
Symantec has populated the predefined content categories with URLs that contain related subject
matter. Symantec regularly updates the content categories. If you have subscribed to the list updates
(that is, you have applied a Content Filtering Subscription license key), you can configure the security
gateway to automatically download updated lists at specified intervals using Symantec LiveUpdate
technology.
Periodically, Symantec may create new predefined content categories to address additional content
areas. If you subscribe to the list updates, these new lists are automatically downloaded along with the
regular updates to existing lists. New lists are not active by default. To deny access to new lists, you
must configure the security gateway.
Predefined content
categories
Predefined content categories are lists of URLs that contain related subject matter. Thirty-
one prepopulated content categories, which include subject matter ranging from
pornography, crime, and violence to news and humor, are currently provided with the
security gateway. Each content category has an associated DDR dictionary.
Dynamic document
review (DDR)
dictionaries
Predefined DDR dictionaries contain key words and phrases, in multiple languages. DDR
dictionaries provide real-time analysis of Web content. DDR dictionaries are used in
conjunction with content categories to provide comprehensive subject matter filtering.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...