01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Adding the action<br />

9 Select Action. Items for adding an action appear in the main window area.<br />

10 Add an action with special settings (Block):<br />

a From the Action list, select Block.<br />

b From the Settings list, select Virus Found.<br />

Rules and rule sets<br />

Rule configuration 4<br />

Under these settings, a block message is sent to the user who requested an object when the<br />

object is blocked.<br />

Reviewing the rule<br />

11 Skip the Events step and select Summary to review what you have configured.<br />

Completing the sample configuration<br />

12 Click Finish. The Add Rule window closes and the new rule appears in the <strong>Gateway</strong> Antimalware rule<br />

set.<br />

Note: The rule is grayed out because it is not enabled.<br />

13 Click Save Changes.<br />

For more information, see About rule sets, Adding a rule, and Block if virus was found (Sample rule).<br />

Sample rules<br />

This section explains in detail three sample rules from the library rule sets of the appliance:<br />

• Do not filter URLs in Global Whitelist<br />

• Block URLs whose category is in Category BlockList<br />

• Block if virus was found<br />

Note: The Block if virus was found rule is also used in another section of this guide as an example for<br />

explaining step by step how a rule is created. For more information, see Create a sample rule.<br />

Do not filter URLs in Global Whitelist (Sample rule)<br />

This rule can be included in rule set for global whitelisting.<br />

Rule<br />

Name<br />

Do not filter URLs in Global Whitelist<br />

Criteria Action<br />

URL matches in list GlobalWhitelist –> Stop Cycle<br />

In plain text, the rule could be rendered as follows:<br />

If a URL is on a particular global whitelist, stop the current processing cycle.<br />

Purpose of the rule<br />

The rule is implemented to provide you with a means of ensuring that particular URLs can be accessed<br />

by the users of your network and are not blocked by any other rules. To achieve this, URLs are entered<br />

on a whitelist. If a whitelist URL is requested, the rule stops processing the request cycle. This means<br />

all following rules of this cycle, including those that might eventually block the URL, are not processed.<br />

When this rule and its rule set are implemented in a rule set system, it should obviously be placed at<br />

the beginning of the system to ensure there are no rule sets before it that block URLs. In this case, the<br />

whitelisting rule is truly global. It overrules all other measures that might be taken for URLs by the<br />

implemented rule set system.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 105

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!