13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Blocking a site permanently2 Modify the default packet-handling properties according to your security policypreferences.For a description of each control, right-click the control, and then click What’s This?3 Click OK.Blocking a site permanentlyThe <strong>WatchGuard</strong> auto-blocking and logging mechanisms help you decide which sitesto permanently block.Use Policy Manager to block a site permanently. The default configuration blocksthree network addresses – 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. These arethe “unconnected” network addresses. Because they are for private use, backbonerouters should never pass traffic with these addresses in the source or destinationfield of an IP packet. Traffic from one of these addresses is almost certainly a spoofedor otherwise suspect address. RFCs 1918, 1627, and 1597 cover the use of theseaddresses.The Blocked Sites list applies only to traffic on the External interface.Connections between the Trusted and Optional interfaces are not subject tothe Blocked Sites list.From the Policy Manager:1 On the toolbar, click the Blocked Sites icon.You can also select Setup => Blocked Sites. The Blocked Sites dialog box appears.2 Click Add.3 Use the Choose Type drop list to select a member type.4 Enter the member value.Depending on the member type, the value can be an IP address, host name, or username.5 Click OK.The Blocked Sites dialog box appears, displaying the new member in the Blocked Sites list.Removing a blocked siteFrom the Blocked Sites dialog box, select the site to remove, and then click Remove.Changing the auto-block durationFrom the Blocked Sites dialog box, either type or use the scroll control to change theduration, in minutes, that the firewall automatically blocks suspect sites. Durationcan range from 1 to 32,767 minutes (about 22 days).Creating exceptions to the Blocked Sites listFrom Policy Manager:1 Select Setup => Blocked Sites Exceptions.The Blocked Sites Exceptions dialog box appears.2 Click Add.44

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!