
296
Controlling traffic at the security gateway
Blocking inappropriate content with content filtering
Content filtering processing order
The security gateway filters email for content in a specific sequence. If a content filtering scanning
process in the sequence is not enabled, the security gateway moves to the next scanning process that is
enabled.
The content filters are applied in the following order:
■
Filtering by URL
See
■
URL filtering using pattern matching
See
“Filtering by URL pattern matching”
■
Filtering by MIME type
See
■
Filtering by file extension
See
■
Filtering by content categories
See
■
Filtering by DDR
See
“About Dynamic Document Review (DDR)”
Note:
If HTTP traffic is denied for any reason, the security gateway stops processing for content
filtering.
Filtering content by allowing or denying access to defined settings
You can filter content at the proxy level based on the following parameters:
After you specify the URLs, URL patterns, MIME types, and file extensions to which users are allowed
or denied access, you can apply these settings selectively in rules. When traffic defined by a rule passes
through the security gateway, the settings are processed in order of precedence, as described in
“Content filtering processing order”
For example, you can create a list of URLs that should be allowed and a second list of file extensions
that should be allowed. When you create a rule that applies these restrictions to HTTP traffic, the
security gateway first applies the list of URLs to the traffic to see if it is allowed. It then applies the list
of file extensions. Only traffic that is defined in both lists is allowed.
Complete these procedures to set up filtering:
■
■
Filtering by URL pattern matching
■
■
Specific URL
You can allow or deny user access to specified URLs.
URL pattern
matching
You can supply pattern matching parameters to block common patterns that indicate
certain types of content.
MIME type
You can allow or deny user access to selected MIME types.
File extension
You can allow or deny user access to specified file extensions.
Содержание Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Страница 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Страница 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Страница 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Страница 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Страница 319: ...318 Controlling traffic at the security gateway Blocking inappropriate content with content filtering...
Страница 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Страница 409: ...408 Providing remote access using VPN tunnels Multicast traffic through gateway to gateway IPsec tunnels...
Страница 509: ...508 Generating reports Upgrade reports...
Страница 553: ...552 Advanced system settings Configuring advanced options...
Страница 557: ...556 SSL server certificate management Installing a signed certificate...
Страница 861: ...860 Index...