Selecting an HTTP Service
User Guide
151
4
Select the rules to determine which packet originators
are automatically added to the auto-blocked sites list.
Selecting an HTTP Service
Because of the extensive security implications of HTTP
traffic, it is important to restrict the incoming service as
much as possible. Many administrators set up public Web
servers only on their optional interface. They restrict
incoming HTTP traffic to the optional interface and pro-
hibit incoming HTTP traffic from traveling from the
optional interface to the trusted interface. Outgoing traffic
is generally less restrictive. For example, many companies
open outgoing HTTP traffic from Any to Any.
WatchGuard Firebox System offers three different types of
HTTP services. Choose the HTTP service that best meets
your needs:
•
Proxied-HTTP
is a multiservice that combines
configuration options for HTTP on port 80 with a rule
that allows (by default) all outgoing TCP connections.
In other words, the Proxied-HTTP is not bilateral
incoming and outgoing; this service controls incoming
TCP traffic only on port 80, but allows outgoing TCP
traffic on all ports. The Proxied-HTTP service includes
Summary of Contents for Firebox X1000
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System...
Page 12: ...xii WatchGuard Firebox System...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System...
Page 61: ...Cabling the Firebox User Guide 39...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System...