30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

13.5 FTP Policy<br />

Weight<br />

Word weight the level of how the word affects possible blocking or allowing of access<br />

to websites. The weight should respect frequency of the particular word in the language<br />

(the more common word, the lower weight) so that legitimate webpages are not blocked.<br />

Description<br />

A comment on the word or group.<br />

13.5 FTP Policy<br />

To define rules for access to FTP servers go to Configuration → Content Filtering → FTP Rules.<br />

Figure 13.13<br />

FTP Rules<br />

Rules in this section are tested from the top of the list downwards (you can order the list<br />

entries using the arrow buttons at the right side of the dialog window). Testing is stopped<br />

when the first convenient rule is met. If the query does not match any rule, access to the FTP<br />

server is implicitly allowed.<br />

Note: The default <strong>Kerio</strong> Control configuration includes a set of predefined rules for FTP traffic.<br />

These rules are disabled by default. These rules are available to the firewall administrators:<br />

• Forbid resume due to antivirus scanning — blocking of download resumption after<br />

interruption (so called resume — FTP command REST).<br />

This rule can increase effectivity of the antivirus control (each file will be checked<br />

as a whole). However, if larger files are transferred, it can be counterproductive<br />

— the probability that a virus code is right at the spot where the interruption took<br />

place is very low and repeating of the whole tranfer would burden Internet connection<br />

redundantly.<br />

For details on antivirus scan of FTP protocol, refer to chapter 14.3.<br />

• Forbid upload — blocking of uploading files to FTP servers. This is one of the methods<br />

that can be used to avoid leak of fragile information from the local network.<br />

• Two rules that block audio and video files downloads — these files are usually large<br />

and their download burdens Internet connection. Besides that, such activity is usually<br />

quite unproductive.<br />

185

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!