12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring the HTTP ProxyThis ruleset gives you control of the cookies in HTTP responses. You can configure rules to strip cookies,based on your network requirements. The default rule for the HTTP-Server and HTTP-Client proxy actionallows all cookies.The Cookies ruleset looks for packets based on the domain associated with the cookie. The domain canbe specified in the cookie. If there is no domain in the cookie, the proxy uses the host name in the firstrequest. Thus, to block all cookies for nosy-adware-site.com, add a rule with the pattern: “*.nosyadware-site.com”.1 From the Categories section on the left, select Cookies.2 Do the steps used to create rules. For more information, see “Defining Rules” on page 161.Setting HTTP body content typesThis ruleset gives you control of the content in an HTTP response. The Firebox is configured to deny Javaapplets, Zip archives, Windows EXE/DLL files, and Windows CAB files. The default proxy action for outgoingHTTP requests (HTTP-Client) allows all other response body content types. We recommend that youexamine the file types that are used in your organization and allow only those file types that are necessaryfor your network.1 From the Categories section, select Body Content Types.2 Do the steps used to create rules. For more information, see “Defining Rules” on page 161.Defining antivirus responses for HTTPThe fields on this dialog box set the actions necessary if a virus is found in an e-mail message. It also setsactions for when an e-mail message contains an attachment that is too large or that the Firebox cannotscan.Although you can use the proxy definition screens to activate and configure Gateway AntiVirus, it is easierto use the Tasks menu in Policy Manager to do this. For more information on how to do this, or to usethe antivirus screens in the proxy definition, see the chapter “Using Signature-Based Security Services.”Changing the deny messageThe Firebox gives a default deny message that replaces the content that is denied. You can replace thatdeny message with one that you write. You can customize the deny message with standard HTML. The178 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!