01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6<br />

<strong>Web</strong> filtering<br />

URL filtering<br />

Rules for URL filtering<br />

Rules that filter URLs are contained in a URL filtering rule set. This section explains an individual<br />

filtering rule and describes the rules in a URL filtering rule set.<br />

A rule set for URL filtering usually includes a blocking rule that blocks access to URLs per category and<br />

one that blocks access according to reputation. A whitelisting rule exempts URLs that should not get<br />

blocked from filtering.<br />

The whitelisting rule is placed before the blocking rules, so it is processed before them. If a requested<br />

URL matches an entry on the whitelist, the rule applies. It stops the processing of the rule set, so the<br />

blocking rules are not processed and cannot apply.<br />

A rule set like this is usually included when the wizard creates a system of rule sets. It is also included<br />

in the default system. There can be several URL filtering rule sets in a rule set system, containing rules<br />

that apply to different user groups.<br />

URL filtering rule sets can differ from each other in that they use different blocking lists and whitelists.<br />

They do not differ, however, in their basic structure, which combines a whitelisting rule with blocking<br />

rules that block URLs individually or according to their categories and reputation scores.<br />

View the implemented URL filtering rules<br />

The URL filtering rules that are implemented on the appliance can be viewed on the user interface.<br />

1 Go to Policy | Rule Sets.<br />

2 On the rule sets tree, go to the rule set that contains the URL filtering rules, which is by default named<br />

URL Filtering. The individual rules appear on the settings pane.<br />

3 On the settings pane, click Show Details. Rule conditions and events are displayed for each rule.<br />

You can modify these rules, delete them, and also create your own rules.<br />

URL filtering rule<br />

This section explains a category blocking rule, which is a key rule type in URL filtering.<br />

Note: The rule is shown here in a notation that comes close to how it appears on the user interface.<br />

Name<br />

Block URLs whose category is in URL Category BlockList<br />

Criteria Action<br />

URL.Categories at least one in list Category BlockList –> Block<br />

In plain text, this rule can be rephrased as follows:<br />

If a URL belongs to a category that is on a blocking list, block access to it.<br />

The property of the rule criteria is URL.Categories. This property is checked for a given URL and the URL<br />

Filter module is called to find the categories the URL belongs to. If these are on the specified blocking<br />

list, the criteria is matched and the rule applies.<br />

The rule then executes its action, which is the Block action. It blocks access to the URL. If a URL<br />

belongs to more than one category, it is blocked if any of these categories is on the list.<br />

The URL.Categories property has the Default settings specified for it. This means the module that<br />

retrieves the category information runs with these settings. The settings determine, for example,<br />

whether a DNS lookup is performed for a URL and category information also searched for based on the<br />

corresponding IP address.<br />

188 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!