01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4<br />

Rules and rule sets<br />

About rule elements<br />

Complex criteria<br />

The criteria of a rule can be made complex by configuring it with two or more parts. Each of the parts<br />

then has a property with operator and operand. The parts are linked by AND or OR.<br />

The following is an example of complex criteria:<br />

AND/OR Property Operator Operand<br />

URL.Categories at least one in list Drugs<br />

OR URL.Categories at least one in list Games/Gambling<br />

The criteria is matched if a filtered URL belongs to a category that is on any of the two specified<br />

category lists (or on both).<br />

If you configure criteria with three or more parts and use both AND and OR between them, you also<br />

need to put brackets to indicate how the parts are logically connected. For example, (a AND b) OR c<br />

differs in meaning from a AND (b OR c).<br />

When you add a third criteria part on the user interface, lowercase letters appear before the parts and<br />

an additional field is inserted at the bottom of the configuration window.<br />

The field displays your criteria parts in short, for example, a AND b OR c. You can then type brackets<br />

into the field as needed.<br />

ID AND/OR Property Operator Operand<br />

a URL.Categories at least one in list Drugs<br />

b AND URL.Categories at least one in list Games/Gambling<br />

c OR Antimalware.Infected<br />

<br />

Criteria Combination (a AND b) OR c<br />

Properties<br />

A property is a key element in every rule. If it has a particular value, the criteria of the rule is matched<br />

and the rule applies, which means that the rule action is triggered.<br />

For example, if the property Antimalware.Infected has the value true in the criteria of a particular rule<br />

for virus and malware filtering, the rule triggers its blocking action.<br />

A property in a rule is a property of a web object or of something that is related to a web object, such<br />

as the user who requests it. For example, Antimalware.Infected is the property of a web object that is<br />

requested by a user or sent in response by a web server or embedded in another object.<br />

A property has a name, a type, and a value. For every property, a particular range of values is possible.<br />

A value within this range is found for it during the filtering process by running a special module or by<br />

going through a particular list.<br />

In the following, some examples of properties are given.<br />

Property of a web page or a file<br />

Property — Antimalware.Infected<br />

Type — Boolean<br />

Values — true | false<br />

The meaning of this property can be paraphrased as “being infected by a virus or other malware”.<br />

A rule using this property could apply if its value is true. The Anti-Malware module scans web objects<br />

when the rule is processed to find out what the value of the property is.<br />

88 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong><br />

equals true

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!