data:image/s3,"s3://crabby-images/b55b7/b55b760971c4e6b5a06a82e4b8afc4170a498d3c" alt="Check Point MAESTRO R80.20SP Скачать руководство пользователя страница 227"
IP and URL Block Feature
Check Point Maestro R80.20SP Administration Guide | 227
Step
Instructions
4
In the Application/Site window:
a.
Enter a name (for example, MyURLs)
You use this name later in the CLI on the Scalable Platform.
b.
From the left, click the
General
page.
c.
In the
General
section, in the
Primary Category
field, select
Custom_Application_
Site
.
d.
In the
Match By
section, click the plus icon (
+
) and add the URL of the web server that
hosts the file with the list of malicious URLs.
Example:
http://192.168.20.30/
Note
- This URL must end with the slash and must not contain the name of
the file (urls.txt).
e.
Click
OK
.
5
In the applicable Access Control policy, add a new rule that drops all traffic that matches the
new Application:
Source
Destination
VPN
Services & Applications
Action
Track
Any
Any
Any
Object of the Custom Application
Drop
None
6
Connect to the command line on the Security Group.
7
Log in to the Expert mode.
8
Configure the URL for the feed:
url_block -a -n <
Name of Custom Application Object
> -p <
URL
of Your Web Server
> ...
Example:
url_block -a -n MyUrls -p http://192.168.20.30/ -z false -r
false
Note
- This can be a file on your own web server.
9
Start the periodic run at the specified intervals:
url_block –i <
INTERVAL
>
10
Examine the configuration:
url_block -l
Example output:
Refresh time interval: 300
MyUrls
Path: http://192.168.20.30/
Zip: false
Regex: false