
278
Controlling traffic at the security gateway
Understanding and using rules
Using content security checks with rules
The security gateway includes content security features that you can use to add protection to rules that
control mail (SMTP and POP3), HTTP, NNTP, and FTP traffic. Protection from destructive content
(viruses), unwanted content (spam) and inappropriate content (Web pages) are all part of content
security.
Once configured, you can apply content security on a per rule basis to provide specific levels of
protection.
Note:
The more content security methods that you use, the greater the protection. However, when you
use multiple content security processes, you will see an impact on performance due to an increased
demand on system resources.
Prerequisites
Complete the following tasks before beginning the procedure:
■
“Protecting your network resources from virus infections”
■
“Increasing productivity by identifying spam email”
■
“Blocking inappropriate content with content filtering”
To use content security checks with rules
1
In the SGMI, in the left pane, under Policy, click
Firewall
.
2
In the right pane, on the Rules tab, select the rule to which you want to add content security checks,
and then click
Properties
.
3
In the Rule Properties dialog box, if the tab for the content security feature you want to use is
greyed out, on the General tab, beside the Service group selection, click
Properties
.
4
In the Service Group Properties dialog box, on the Protocols tab, to add the required protocol, click
Add.
5
In the Select protocol dialog box, use the following suggestions for the protocols you want:
■
Antivirus
SMTP, POP3, HTTP, or FTP
■
Antispam
SMTP or POP3
■
Content filtering
HTTP or NNTP
6
Click
OK
.
7
In the Rule Properties dialog box, if the service group for the rule contains the HTTP protocol, on
the Miscellaneous tab, check
Application data scanning
.
8
On the Antivirus tab, to enable scanning of SMTP, POP3, HTTP, or FTP files, check the desired
protocol, and then under each, select the antivirus features to be used.
9
On the Antispam tab, check one or more spam detection methods.
10
On the Content Filtering tab, in the Content profile drop-down list, select a content profile.
11
Under Select the protocols and settings to apply content filter scanning, do any of the following:
■
To enable HTTP, check HTTP, and then check the HTTP restrictions you want to enable.
■
To enable newsgroups, check NNTP, and then in the Newsgroup profile drop-down list, select
the newsgroup profile.
Содержание Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Страница 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Страница 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Страница 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Страница 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Страница 319: ...318 Controlling traffic at the security gateway Blocking inappropriate content with content filtering...
Страница 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Страница 409: ...408 Providing remote access using VPN tunnels Multicast traffic through gateway to gateway IPsec tunnels...
Страница 509: ...508 Generating reports Upgrade reports...
Страница 553: ...552 Advanced system settings Configuring advanced options...
Страница 557: ...556 SSL server certificate management Installing a signed certificate...
Страница 861: ...860 Index...