12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Defining RulesThe fields you use for these rule definitions look the same for each category of ruleset. The simple viewis shown below. You can also select Change View to see the advanced view.Use the advanced view to improve the matching function of a proxy. In advanced view, you can configureexact match and Perl-compatible regular expressions. In simple view, you can configure wildcardpattern matching with simple regular expressions.Adding rulesetsFrom the simple view, do these steps to add new rules:1 In the Pattern text box, type a pattern that uses simple regular expression syntax.The wildcard for zero or more than one character is “*”.The wildcard for one character is “?”.2 Click Add.The new rule appears in the Rules box.3 In the Actions to take section, the If matched drop-down list sets the action to do if the contents ofa packet match one of the rules in the list. The None matched drop-down list sets the action to do ifthe contents of a packet do not match a rule in the list. Below is a list of all possible actions. Theactions Strip and Lock apply only to signature-based intrusion prevention actions.AllowAllows the connection.DenyDenies a specific request but keeps the connection if possible.DropDenies the specific request and drops the connection.BlockDenies the request, drops the connection, and adds the source host to the Blocked Sites list. Formore information on blocked sites, see “Setting Blocked Sites” on page 135.StripRemoves an attachment from a packet and discards it. The other parts of the packet are sentthrough the Firebox to its destination.162 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!