316
Controlling traffic at the security gateway
Blocking inappropriate content with content filtering
Adding content filtering protection to a rule
You can create or modify a rule to select the methods that you want to use to filter content. The more
content filtering processes that you enable, the greater the demand on network and disk resources.
You can create content profiles when you set up a rule. You can also create content profiles when you
configure content filtering options. You can view, edit, create, and delete any of the content profiles in
either place in the SGMI.
After you enable the content filtering processes that you want to use, you can configure the content
filtering settings in the SGMI under Policy on the Content Filtering tab.
Prerequisites
Complete the following task before beginning this procedure:
■
To add content filtering protection to a rule
1
In the SGMI, in the left pane, under Policy, click
Firewall
.
2
In the right pane, on the Rules tab, highlight the rule to which you want to add content filtering,
and then click
Properties
.
3
In the Rule Properties dialog box, on the General tab, to the right of the Service group field, click
the Properties button.
4
In the Service Group Properties dialog box, on the Protocols tab, ensure that one of the following is
listed:
■
If you want to apply a content profile and HTTP restrictions, use HTTP.
■
If you want to apply a newsgroup profile, use NTP.
Click
OK
.
5
In the rule properties dialog box, on the Content Filtering tab, under Select a content profile to
apply when scanning the selected protocols, select a content profile from the Content profile drop-
down list:
6
To apply HTTP filtering, under Select the protocols and settings, to apply content filtering
scanning, check
HTTP
.
7
When you enable content filtering on HTTP traffic, optionally, you can check any of the following
check boxes:
8
To apply filtering to newsgroups through the Network News Protocol, check
NNTP
.
9
If you enable content filtering on NTTP traffic, from the Newsgroup profile drop-down list, select a
newsgroup profile.
10
Click
OK
.
11
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Apply URL restrictions
To enable the URL allow or deny list, check this option.
Apply URL pattern match restrictions To enable the blocking of URLs based on pattern matching, check
this option.
Apply MIME type restrictions
To enable the MIME type allow or deny list, check this option.
Apply file extension restrictions
To enable the File Extensions allow or deny list, check this option.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...