11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 15: Controlling Web Site AccessCreating WebBlocker exceptionsWebBlocker provides an exceptions control to override anyof the WebBlocker settings. Exceptions take precedenceover all other WebBlocker rules; you can add sites that youwant to be allowed or denied above and beyond otherWebBlocker settings. Sites listed as exceptions apply onlyto HTTP traffic and are not related to the Blocked Sites list.The exceptions option maintains a list of IP addresses thatyou want to either specifically allow or deny, regardless ofother WebBlocker settings. You can specify exceptions bydomain name, network address, or host IP address. Youcan also fine-tune your exceptions by specifying a portnumber, path name, or string which is to be blocked for aparticular Web site. For example, if you wanted to blockonly www.sharedspace.com/~dave, because Dave’s site containsnude pictures, you would enter “~dave” to block thatdirectory of sharedspace.com. This would still allow users tohave access to www.sharedspace.com/~julia, which containsa helpful article on increasing productivity.If you wanted to block any sexually explicit content thatmight be on sharedspace.com, you might enter *sex, toblock a Web page such as www.sharedspace.com/~george/sexy.htm. By placing an asterisk (*) in front of the string youwant to match, it will be matched if that string appearsanywhere in the location part of the URL. However, youcannot enter *sex in the pattern section, and expect toblock all URLs that contain the word “sex.” The * optioncan be used only to modify the exceptions within a specificURL. For example, you can block www.sharedspace.com/*sex and expect that www.sharedspace/sexsite.html will beblocked.NOTEThis WebBlocker features is applicable only for outboundrequests to access web sites. You cannot use WebBlockerexceptions to make an internal host exempt fromWebBlocker rules.260 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!