WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 15: Controlling Web Site AccessInstalling the WebBlocker serverYou install the WebBlocker server when you first run thesetup program for the WatchGuard Firebox System, asdescribed in “Setting Up the Management Station” onpage 36. By default, the setup program installs the Web-Blocker server on the same server as the WatchGuard SecurityEvent Processor. However, to preserve performance ifyou are running WFS under high load conditions, considerinstalling the WebBlocker server on a dedicated server runningWindows NT 4.0. or Windows 2000.To install the WebBlocker server on a dedicated platform,rerun the setup program on the dedicated server and–onthe Select Components screen–unselect all componentsexcept the WebBlocker server.You must start the WebBlocker server for WebBlockerrequests from the Firebox to be processed.Downloading the database usingWebBlocker UtilityAfter you install the WebBlocker server, you are askedwhether you want to run the WebBlocker utility. Click Yes.The WebBlocker Utility dialog box appears, as shown inthe following figure. Select Download Database to downloadthe current database.NOTEThe WebBlocker database is over 60 MB in size and maytake 30 minutes or more to download.254 WatchGuard Firebox System

Getting Started with WebBlockerYou can run the WebBlocker utility at any time to:• Download a new version of the database.• View the current database status• Upload the database• View the current WebBlocker server status• Install or remove the server• Start or stop the serverTo run the WebBlocker utility, select Start => Programs =>WatchGuard => WebBlocker Utility.Configuring the WatchGuard service iconBecause WebBlocker relies on copying updated versions ofthe WebBlocker database to the event processor, you mustconfigure the WatchGuard service setting Allow Outgoingto Any. It is possible to narrow this setting and use the IPaddress of webblocker.watchguard.com. However, thisaddress may change without notice.Add an HTTP serviceTo use WebBlocker, add the Proxied-HTTP, Proxy, or HTTPservice. WatchGuard recommends using Proxied-HTTP,which provides filtering on all ports. (HTTP without theProxy service manages only port 80.) WebBlocker takesprecedence over other settings in the HTTP or Proxy ser-User Guide 255

Chapter 15: Controlling Web Site AccessInstalling the WebBlocker serverYou install the WebBlocker server when you first run thesetup program for the <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>, asdescribed in “Setting Up the Management Station” onpage 36. By default, the setup program installs the Web-Blocker server on the same server as the <strong>WatchGuard</strong> SecurityEvent Processor. However, to preserve performance ifyou are running WFS under high load conditions, considerinstalling the WebBlocker server on a dedicated server runningWindows NT 4.0. or Windows 2000.To install the WebBlocker server on a dedicated platform,rerun the setup program on the dedicated server and–onthe Select Components screen–unselect all componentsexcept the WebBlocker server.You must start the WebBlocker server for WebBlockerrequests from the <strong>Firebox</strong> to be processed.Downloading the database usingWebBlocker UtilityAfter you install the WebBlocker server, you are askedwhether you want to run the WebBlocker utility. Click Yes.The WebBlocker Utility dialog box appears, as shown inthe following figure. Select Download Database to downloadthe current database.NOTEThe WebBlocker database is over 60 MB in size and maytake 30 minutes or more to download.254 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!