01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

6<br />

<strong>Web</strong> filtering<br />

Global whitelisting<br />

Global whitelisting<br />

URLs and other web objects can be placed on global whitelists to skip all further filtering for related<br />

requests. This section explains global whitelisting and describes a library rule set for this function, as<br />

well as some lists used by the whitelisting rules.<br />

Rules for global whitelisting<br />

This section explains what a global whitelisting rule set does and describes a sample library rule set.<br />

A rule set for global whitelisting contains at least one whitelisting rule for a particular object type, for<br />

example, for URLs. The rule uses a list to stop the filtering cycle for web objects that have been entered<br />

onto it.<br />

The rule set is typically placed at the beginning of a rule set system and before the rule sets that do<br />

virus and malware filtering, URL filtering, and other filtering jobs. This way, all these rule sets are not<br />

processed in the current cycle when the rule or rules of the global whitelisting rule set apply.<br />

The impact of the rule set is global because it does not only disable a particular kind of filtering, but all<br />

filtering that would have been executed after it in the filtering process.<br />

Global Whitelist<br />

This section describes the rules in a library rule set that exempts requests from all further filtering when<br />

they are related to web objects on particular lists.<br />

For general information on understanding and handling rules, see Rules and rule sets.<br />

Library rule set — Global Whitelist<br />

Criteria — Always<br />

Cycle — Requests (and IM), responses, embedded objects<br />

The rule set contains the following rules:<br />

Client IP is in list Allowed Clients<br />

Client.IP is in list Allowed Clients –> Stop Cycle<br />

The rule uses the Client.IP property to check whether the IP address of a client that a request was<br />

sent from is on the specified whitelist. If it is, the rule applies and stops the current processing<br />

cycle. The request is then forwarded to the appropriate web server.<br />

URL.Host matches in list Global Whitelist<br />

URL.Host matches in list Global Whitelist –> Stop Cycle<br />

The rule uses the URL.Host property to check whether the host that a URL sent in a request<br />

provides access to is on the specified whitelist. If it is, the rule applies and stops the current<br />

processing cycle. The request is then forwarded to the web server that is the requested host.<br />

214 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!