It is also important to understand that although whitelisting prevents a particular source from
being blacklisted, it still does not prevent NetDefendOS mechanisms such as threshold rules
from dropping or denying connections from that source. What whitelisting does is prevent a
source being added to a blacklist if that is the action a rule has specified.
For further details on usage see
Section 6.6.7, “Setting Up IDP”
and
Section 10.3, “Threshold Rules”
Note: The content filtering blacklist is separate
Content filtering blacklisting is a separate subject and uses a separate logical list (see
Section 6.3, “Web Content Filtering”).
The CLI blacklist Command
The
blacklist
command can be used to look at as well as manipulate the current contents of the
blacklist and the whitelist. The current blacklist can be viewed with the command:
gw-world:/> blacklist -show -black
This
blacklist
command can be used to remove a host from the blacklist using the
-unblock
option.
Example 6.33. Adding a Host to the Whitelist
In this example we will add an IP address object called
white_ip
to the whitelist. This will mean
this IP address can never be blacklisted.
Command-Line Interface
gw-world:/> add BlacklistWhiteHost Addresses=white_ip Service=all_tcp
Web Interface
1.
Go to: System > Advanced Settings > Whitelist > Add > Whitelist host
2.
Now select the IP address object
white_ip
so it is added to the whitelist
3.
Select the service
all_tcp
to be associated with this whitelist entry
4.
Click OK
Chapter 6: Security Mechanisms
572
Содержание NetDefendOS
Страница 30: ...Figure 1 3 Packet Flow Schematic Part III Chapter 1 NetDefendOS Overview 30 ...
Страница 32: ...Chapter 1 NetDefendOS Overview 32 ...
Страница 144: ...Chapter 2 Management and Maintenance 144 ...
Страница 220: ... Enable DHCP passthrough Enable L2 passthrough for non IP protocols 4 Click OK Chapter 3 Fundamentals 220 ...
Страница 267: ... SourceNetwork lannet DestinationInterface any DestinationNetwork all nets 4 Click OK Chapter 3 Fundamentals 267 ...
Страница 284: ...Chapter 3 Fundamentals 284 ...
Страница 360: ...The ospf command options are fully described in the separate NetDefendOS CLI Reference Guide Chapter 4 Routing 360 ...
Страница 392: ...Chapter 4 Routing 392 ...
Страница 396: ...Web Interface 1 Go to Network Ethernet If1 2 Select Enable DHCP 3 Click OK Chapter 5 DHCP Services 396 ...
Страница 419: ... Host 2001 DB8 1 MAC 00 90 12 13 14 15 5 Click OK Chapter 5 DHCP Services 419 ...
Страница 420: ...Chapter 5 DHCP Services 420 ...
Страница 424: ...2 Now enter Name lan_Access Action Expect Interface lan Network lannet 3 Click OK Chapter 6 Security Mechanisms 424 ...
Страница 573: ...Chapter 6 Security Mechanisms 573 ...
Страница 575: ...This section describes and provides examples of configuring NAT and SAT rules Chapter 7 Address Translation 575 ...
Страница 607: ...Chapter 7 Address Translation 607 ...
Страница 666: ...Chapter 8 User Authentication 666 ...
Страница 775: ...Chapter 9 VPN 775 ...
Страница 819: ...Chapter 10 Traffic Management 819 ...
Страница 842: ...Chapter 11 High Availability 842 ...
Страница 866: ...Default Enabled Chapter 13 Advanced Settings 866 ...
Страница 879: ...Chapter 13 Advanced Settings 879 ...