Firewall Protection Profile
SSL content scanning and inspection
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
403
•
FortiGuard Web
Filtering
FortiGuard Web Filtering options for HTTPS:
•
Enable FortiGuard Web Filtering
•
Enable FortiGuard Web Filtering Overrides
•
Provide details for blocked HTTP 4xx and 5xx errors
•
Rate images by URL (blocked images will be replaced with blanks)
•
Allow websites when a rating error occurs
•
Strict Blocking
•
Rate URLs by domain and IP address
Go to
Firewall > Profile
. Add or edit a protection profile and configure
Web
Filtering > FortiGuard Web Filtering
for HTTPS. For more information, see
“FortiGuard Web Filtering options” on page 413
Spam Filtering
Spam filtering options for IMAPS, POP3S, and SMTPS:
•
FortiGuard AntiSpam IP address check, URL check, E-mail checksum
check, and Spam submission
•
IP address BWL check
•
HELO DNS lookup
•
E-mail address BWL check
•
Return e-mail DNS check
•
Banned word check
•
Spam Action
•
Tag Location
•
Tag Format
Go to
Firewall > Protection Profile
. Add or edit a protection profile and
configure
Spam Filtering
for IMAPS, POP3S, and SMTPS. For more
information, see
“Spam Filtering options” on page 416
Data Leak Prevention
DLP for HTTPS, IMAPS, POP3S, and SMTPS. To apply DLP, follow the
steps below:
•
Go to
UTM > Data Leak Prevention > Rule
to add DLP rules. For
HTTPS, add an HTTP rule and select HTTPS POST and HTTPS GET.
For IMAPS, POP3S, and SMTPS, add an Email rule and select
IMAPS, POP3S, and SMTPS. See
“Adding or configuring DLP rules”
•
Go to
UTM > Data Leak Prevention > Sensor
and add the DLP rules to
a DLP sensor. See
“Adding or editing a rule in a DLP sensor” on
•
Go to
Firewall > Protection Profile
. Add or edit a protection profile and
use
Data Leak Prevention Sensor
to add the DLP sensor to a
protection profile.
Note
: In a protection profile, if you set
Protocol
Recognition >
HTTPS Content Filtering Mode
to
URL Filtering
, DLP
rules
cannot
inspect HTTPS. Set this option to
Deep Scan
.
•
Go to
Firewall > Policy
and add the protection profile to a firewall
policy. See
“Data Leak Prevention Sensor options” on page 419
.
Content summary
content archiving
Content summary content archiving for HTTPS, IMAPS, POP3S, and
SMTPS. Add DLP rules to the protocol. All DLP rules perform content
summary content archiving for the content that they match. For summary
content archiving, you must configure the FortiGate unit to send log
messages to a FortiAnalyzer unit or to the FortiGuard Analysis and
Management Service (FAMS).
To view content summary information go to
Log&Report > Content
Archive
. Select
Web
to view HTTPS content summary information. Select
to view IMAPS, POP3S, and SMTPS content summary information.
For more information, see
Full content archiving
Full content archiving for HTTPS, IMAPS, POP3S, and SMTPS. Add DLP
rules for the protocol to a DLP sensor and select
Archive
for full content
archiving. DLP rules with
Archive
selected in a DLP sensor perform full
content archiving for the content that they match. For full content
archiving, you must also configure the FortiGate unit to send log
messages to a FortiAnalyzer unit.
To view archived content go to
Log&Report > Content Archive
. Select
Web
to view HTTPS content. Select
to view IMAPS, POP3S, and
SMTPS content.
For more information, see
Содержание Gate 60D
Страница 678: ...Reports Log Report FortiGate Version 4 0 Administration Guide 678 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 704: ...Index FortiGate Version 4 0 Administration Guide 704 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 705: ...www fortinet com...
Страница 706: ...www fortinet com...