WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies WSM User Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
12.07.2015 Views

Configuring WebBlocker2 Select the policy you want to configure and click Configure.The WebBlocker Configuration dialog box for that policy appears.The WebBlocker Configuration dialog box includes tabs to configure servers, categories, exceptions,and advanced settings.Adding new serversYou can add more than one WebBlocker Server so the Firebox® can fail over to a backup server if it cannotconnect to the primary server. The first server in the list is the primary server. You cannot add morethan five WebBlocker Servers to a configuration.1 To add a server, click the plus sign (+).The Add WebBlocker Server dialog box appears.2 Next to Server IP, type the IP address of the WebBlocker Server. Type the port number.Selecting categories to blockWhen you used the Activate WebBlocker wizard, you selected categories of web sites you want to block.You can use this dialog box to make changes to your original configuration. Select the check box adjacentto the categories of web sites you want to block. To read a description of the category, click on it.The description appears in the box at the bottom of the screen. If you want to block access to web sitesthat match any category, select Deny All Categories.NoteTo stop users from going to anonymizer web sites to try to avoid WebBlocker, select to block the RemoteProxies category in WebBlocker.294 WatchGuard System Manager

Configuring WebBlockerDefining WebBlocker exceptionsYou can override a WebBlocker action with an exception. You can add a web site that is allowed ordenied as an exception to the WebBlocker categories. The web sites you add apply only to HTTP traffic.They are not added to the Blocked Sites list.The exceptions are based on URL patterns, not IP addresses. You can have the Firebox block an URL withan exact match. Usually, it is more convenient to have the Firebox look for URL patterns. The URL patternsdo not include the leading "http://". To match a URL path on all web sites, the pattern must have aleading “/*”.The host in the URL can be the host name specified in the HTTP request, or the IP address of the server.Network addresses are not supported at this time, though you can use subnets in a pattern (for example,10.0.0.*).For servers on port 80, do not include the port. For servers on ports other than 80, add “ :port”, for example:10.0.0.1:8080. You can also use a wildcard for the port—for example,10.0.0.1:*—but this does notapply to port 80.You can create WebBlocker exceptions with the use of any part of a URL. You can set a port number, pathname, or string that must be blocked for a special web site. For example, if it is necessary to block onlywww.sharedspace.com/~dave because it has inappropriate photographs, you type “www.sharedspace.com/~dave/*”.This gives the users the ability to browse to www.sharedspace.com/~julia, whichcould contain content you want your users to see.To block URLs that contain the word “sex” in the path, you can type “*/*sex*”. To block URLs that contain“sex” in the path or the host name, type “*sex*”.You can block ports in an URL. For example, look at the URL http://www.hackerz.com/warez/index.html:8080. This URL has the browser use the HTTP protocol on TCP port 8080 instead of thedefault method that uses TCP 80. You can block the port by matching *8080.1 To create exceptions to the WebBlocker categories, click the Exceptions tab.2 Click the “+” sign to add a new exception rule.User Guide 295

Configuring WebBlocker2 Select the policy you want to configure and click Configure.The WebBlocker Configuration dialog box for that policy appears.The WebBlocker Configuration dialog box includes tabs to configure servers, categories, exceptions,and advanced settings.Adding new serversYou can add more than one WebBlocker Server so the Firebox® can fail over to a backup server if it cannotconnect to the primary server. The first server in the list is the primary server. You cannot add morethan five WebBlocker Servers to a configuration.1 To add a server, click the plus sign (+).The Add WebBlocker Server dialog box appears.2 Next to Server IP, type the IP address of the WebBlocker Server. Type the port number.Selecting categories to blockWhen you used the Activate WebBlocker wizard, you selected categories of web sites you want to block.You can use this dialog box to make changes to your original configuration. Select the check box adjacentto the categories of web sites you want to block. To read a description of the category, click on it.The description appears in the box at the bottom of the screen. If you want to block access to web sitesthat match any category, select Deny All Categories.NoteTo stop users from going to anonymizer web sites to try to avoid WebBlocker, select to block the RemoteProxies category in WebBlocker.294 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!