18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 6: Configuring Application Defenses<br />

Creating Web or Secure Web Application Defenses<br />

166<br />

• Modify an existing filter rule—To modify an existing filter rule, select the<br />

rule you want to modify, and click Modify. See “Configuring MIME<br />

filtering rules” on page 166. (If you are modifying the default MIME<br />

filtering rule, see “Configuring the Default filtering rule action” on page<br />

168.)<br />

• Delete a filter rule—To delete an existing filter rule, select the rule you<br />

want to delete and click Delete. You will be prompted to confirm your<br />

decision.<br />

2 Determine how infected files will be handled in the Infected File Handling<br />

area as follows:<br />

• To discard infected files, select Discard Infected Files.<br />

• To remove the virus from the file and then continue processing the file,<br />

select Repair Infected Files.<br />

3 To reject all files in the event that scanning is not available, select the<br />

Reject All Files If Scanning Is Unavailable check box. If you select this<br />

option, the connection will be dropped if scanning is unavailable.<br />

4 In the Scan File Size Limit (KB) field, specify the maximum file size that will<br />

be allowed in KB. If a file exceeds the size specified in this field, filtering will<br />

not take place and the file will be denied.<br />

Configuring MIME filtering rules<br />

When you click New or Modify beneath the MIME/Virus/Spyware Filter Rules<br />

area, the MIME/Virus/Spyware Rule Edit window appears. This window allows<br />

you to add or modify MIME/Virus/Spyware filtering rules.<br />

Important: Rules that are configured with an allow or deny action will allow or deny<br />

traffic based on the rule criteria that is defined for those rules. Allow and deny rules<br />

do not perform virus scanning. To perform virus scanning for traffic that matches a<br />

rule before it is allowed, you must specify Virus/Spyware Scan in the rule’s Action<br />

field.<br />

By default, a single allow rule is contained in the filter rule table. If you choose<br />

to leave the default allow rule as the last rule in your table (that is, all traffic that<br />

isn’t explicitly denied will be allowed), you will need to configure the appropriate<br />

virus scan and/or deny rules and place them in front <strong>of</strong> the default allow rule. If<br />

you configure the default rule action to deny (that is, all traffic that is not<br />

explicitly allowed will be denied) you will need to configure the appropriate<br />

virus scan and/or allow rules and place them in front <strong>of</strong> the default deny rule.<br />

To create MIME/Virus/Spyware rules, follow the steps below.<br />

Note: Rules that specify both a MIME type/subtype and file extensions will allow or<br />

deny any traffic that matches either the MIME Type or a File Extension type. That<br />

is, the traffic does not need to match both criteria to match the rule.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!