
295
Controlling traffic at the security gateway
Blocking inappropriate content with content filtering
To use packet filters as forwarding filters
1
In the SGMI, in the left pane, under Policy, click
Policy Parameters
.
2
In the right pane, under Forward Filter, in the Packet filter drop-down list, select a packet filter to
use as a forwarding filter.
3
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
Blocking inappropriate content with content filtering
With the exponential growth of the World Wide Web, much of the traffic on the Internet is HTTP
traffic. The security gateway offers a variety of tools for managing Web access for both incoming and
outgoing traffic. You can customize HTTP and NNTP access to and from designated entities within
your network using the content management tools that are available through the security gateway.
To configure content filtering, you can do the following:
■
Configure rules for the HTTP proxy that allow or deny traffic based on URL address, URL pattern
matching, MIME type, and file extensions. Configuring the firewall to provide filtering based on
these parameters conserves resources and increases overall efficiency. These settings apply on a
per-rule basis. You must have a valid Firewall Base license to enable any of the HTTP settings.
■
Configure content profiles that provide content filtering based on the subject matter of Web
content. Content profiles are applied on a per-rule basis and let you customize content filtering for
different levels of users on your network. You must have a valid content security license to enable
these settings. A valid content security subscription license lets you receive updated Dynamic
Document Review (DDR) and content category definitions through LiveUpdate.
■
Configure newsgroup profiles that provide content filtering based on the subject matter of
newsgroups. Newsgroup profiles are applied on a per rule basis and let you customize content
filtering for different levels of users on your network. You must have a valid content security
license to enable NNTP settings. A valid Content Security subscription license lets you receive
updated DDR and Content Category definitions through LiveUpdate.
■
Specify limits for handling container files to protect against denial-of-service attacks. These
attacks can occur with container files that are large, that contain large numbers of embedded
compressed files, or that have been designed to maliciously use resources and degrade
performance. You set these limits using the Antivirus Configuration tab. They are applied when
you create a DDR-enabled content profile and apply it to a rule.
Related information
For further information related to this topic, see the following:
■
“Filtering content by allowing or denying access to defined settings”
■
■
“Preventing denial of service attacks”
■
“Understanding and using licenses”
■
Содержание Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Страница 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Страница 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Страница 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Страница 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Страница 319: ...318 Controlling traffic at the security gateway Blocking inappropriate content with content filtering...
Страница 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Страница 409: ...408 Providing remote access using VPN tunnels Multicast traffic through gateway to gateway IPsec tunnels...
Страница 509: ...508 Generating reports Upgrade reports...
Страница 553: ...552 Advanced system settings Configuring advanced options...
Страница 557: ...556 SSL server certificate management Installing a signed certificate...
Страница 861: ...860 Index...