WSM User Guide - WatchGuard Technologies
WSM User Guide - WatchGuard Technologies WSM User Guide - WatchGuard Technologies
Customizing spamBlocker Using Multiple Proxies3 From Firebox System Manager, click the Security Services tab.The statistics for spamBlocker appear at the bottom of the screen.Customizing spamBlocker Using Multiple ProxiesYou can configure more than one SMTP Proxy service to use spamBlocker. This lets you create customrules for different groups in an organization. For example, you can allow all e-mail to your managementand use a spam tag for the marketing team.If you want to use more than one SMTP Proxy service with spamBlocker, your network must use one ofthese configurations:• Each SMTP proxy policy must send e-mail to a different internal e-mail server.or• You must set the external source or sources that can send e-mail for each SMTP proxy policy.NotespamBlocker does not detect spam in outbound SMTP e-mail.306 WatchGuard System Manager
CHAPTER 25Using Signature-Based SecurityServicesHackers use many methods to attack computers on the Internet. These attacks (called intrusions in thischapter) are created to cause damage to your network, get sensitive information, or use your computersto attack other networks.WatchGuard® offers the Gateway AntiVirus/Intrusion Prevention Service (GAV/IPS) that can identify andstop a possible intrusion. The Intrusion Prevention Service operates with all WatchGuard proxies. Watch-Guard Gateway AntiVirus operates with the SMTP, HTTP, and TCP proxies.When a new intrusion attack is identified, the features that make the virus or attack unique are recorded.These recorded features are known as the signature. GAV/IPS uses these signatures to find viruses andintrusion attacks.New viruses and intrusion methods appear on the Internet frequently. To make sure that GAV/IPS givesyou the best protection, you must update the signatures frequently. You can configure the Firebox® toupdate the signatures automatically from WatchGuard. You can also update the signatures manually.NoteWatchGuard cannot guarantee that the product can stop all viruses or intrusions, or prevent damage toyour systems or networks from a virus or intrusion attack.User Guide 307
- Page 274 and 275: Working with Devices on a Managemen
- Page 276 and 277: Working with Devices on a Managemen
- Page 278 and 279: Scheduling Firebox X Edge Firmware
- Page 280 and 281: Using the Firebox X Edge Management
- Page 282 and 283: Using the Firebox X Edge Management
- Page 284 and 285: Using the Firebox SOHO 6 Management
- Page 286 and 287: Creating and Applying Edge Configur
- Page 288 and 289: Creating and Applying Edge Configur
- Page 290 and 291: Creating and Applying Edge Configur
- Page 292 and 293: Managing Firebox X Edge Network Set
- Page 294 and 295: Using AliasesNaming aliases on the
- Page 296 and 297: Using Aliases3 Click Aliases.The al
- Page 298 and 299: Configuring WINS and DNS Servers•
- Page 300 and 301: Adding New Users to the PPTP_Users
- Page 302 and 303: Preparing the Client Computers- To:
- Page 304 and 305: Creating and Connecting a PPTP RUVP
- Page 306 and 307: Creating and Connecting a PPTP RUVP
- Page 308 and 309: Getting Started with WebBlocker4 In
- Page 310 and 311: Activating WebBlocker4 Click Next.5
- Page 312 and 313: Configuring WebBlocker2 Select the
- Page 314 and 315: Configuring WebBlocker3 Click the A
- Page 316 and 317: Scheduling a WebBlocker Action298 W
- Page 318 and 319: Installing the Software Licensespam
- Page 320 and 321: Activating spamBlocker3 From Policy
- Page 322 and 323: Creating Rules for Bulk and Suspect
- Page 326 and 327: Installing the Software LicensesIns
- Page 328 and 329: Configuring Gateway AntiVirusConfig
- Page 330 and 331: Configuring Gateway AntiVirus2 To s
- Page 332 and 333: Activating Intrusion Prevention (IP
- Page 334 and 335: Configuring Intrusion PreventionCon
- Page 336 and 337: Configuring Intrusion Prevention2 S
- Page 338 and 339: Configuring Intrusion PreventionCon
- Page 340 and 341: Getting Intrusion Prevention Servic
- Page 342 and 343: Creating QoS Actionsmanagement syst
- Page 344 and 345: Dynamic RoutingDynamic RoutingA rou
- Page 346 and 347: Using RIPSection Command Descriptio
- Page 348 and 349: Using RIP2 In the New Policy Proper
- Page 350 and 351: Using OSPF2 In the New Policy Prope
- Page 352 and 353: Using OSPFSection Command Descripti
- Page 354 and 355: Using OSPF4 Click Import to import
- Page 356 and 357: Using BGPRegion Registry Name Web S
- Page 358 and 359: Using BGPConfiguring Fireware Pro t
- Page 360 and 361: Using BGP342 WatchGuard System Mana
- Page 362 and 363: Selecting a Primary High Availabili
- Page 364 and 365: Configuring HA for Firebox X (non e
- Page 366 and 367: Upgrading Software in an HA Configu
- Page 368 and 369: (B) To use the SOFTWARE PRODUCT on
- Page 370 and 371: RENEWAL/UPGRADE REQUEST WILL NOT BE
- Page 372 and 373: conditions of use by WatchGuard of
CHAPTER 25Using Signature-Based SecurityServicesHackers use many methods to attack computers on the Internet. These attacks (called intrusions in thischapter) are created to cause damage to your network, get sensitive information, or use your computersto attack other networks.<strong>WatchGuard</strong>® offers the Gateway AntiVirus/Intrusion Prevention Service (GAV/IPS) that can identify andstop a possible intrusion. The Intrusion Prevention Service operates with all <strong>WatchGuard</strong> proxies. Watch-Guard Gateway AntiVirus operates with the SMTP, HTTP, and TCP proxies.When a new intrusion attack is identified, the features that make the virus or attack unique are recorded.These recorded features are known as the signature. GAV/IPS uses these signatures to find viruses andintrusion attacks.New viruses and intrusion methods appear on the Internet frequently. To make sure that GAV/IPS givesyou the best protection, you must update the signatures frequently. You can configure the Firebox® toupdate the signatures automatically from <strong>WatchGuard</strong>. You can also update the signatures manually.Note<strong>WatchGuard</strong> cannot guarantee that the product can stop all viruses or intrusions, or prevent damage toyour systems or networks from a virus or intrusion attack.<strong>User</strong> <strong>Guide</strong> 307