01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4<br />

Rules and rule sets<br />

Rule configuration<br />

Create a sample rule<br />

This section explains in detail how to create a sample rule. Creating new rules is one of the activities<br />

you can complete to modify the implemented rule set system.<br />

Note: The rule already exists in one of the library rule sets, but under a slightly different name (Block if virus<br />

was found).<br />

Rule<br />

Name<br />

Block if virus was detected<br />

Criteria Action<br />

Antimalware.Infected equals true –> Block<br />

Procedure<br />

Complete the following procedure to create this rule:<br />

Note: Comments in italics explain what you are doing through the step or steps that follow.<br />

1 Go to Policy | Rule Sets.<br />

Choosing a rule set for the rule<br />

2 From the rule sets tree, select <strong>Gateway</strong> Antimalware as the rule set for the rule. The rule set and<br />

its current rules appear on the settings pane.<br />

Opening the Add Rule window<br />

3 On the settings pane, click Add Rule. The Add Rule Window opens with the Name step selected. In<br />

the main window area, items appear for adding a name and other general settings.<br />

Adding general settings<br />

4 Add the following general settings:<br />

a Name — Type Block if virus was detected.<br />

b Enable rule — Deselect this checkbox, so the sample rule gets not enabled.<br />

c Comment — Skip this optional substep.<br />

Adding the criteria<br />

5 Select Rule Criteria. Items for adding the criteria appear.<br />

6 Click Add. The Add Criteria window opens.<br />

7 Add the criteria of the rule (Antimalware.Infected ... equals true):<br />

a From the Property list, select Antimalware.Infected.<br />

b In the Settings list, leave the default, which is <strong>Gateway</strong> Antimalware .<br />

The Anti-Malware module runs with these settings when it scans web objects, using virus<br />

signatures and proactive methods.<br />

c In the Operator list, leave equals, the default value.<br />

d In the Parameter area, select true from the Value list as operand (parameter) for the criteria.<br />

Note: (Boolean) is displayed in brackets next to Parameter. Antimalware.Infected is a property of the<br />

Boolean type. When it is selected, its parameter must have the same type.<br />

8 Click OK. The Add Criteria window closes and the added criteria appears in the main window area.<br />

104 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!