McAfee MAP-3300-SWG Product Guide - Page 187

Anti-Virus Settings — Custom Malware Options, HTTPS Web Categorization Settings

Page 187 highlights

Overview of Web features Web Policies Anti-Virus Settings - Custom Malware Options Use this page to specify the actions to take when some types of malicious software ("malware") are detected. Email | Email Policies | Scanning Policies [Anti-virus] | Custom Malware Options Web | Web Policies | Scanning Policies [Anti-Virus] | Custom Malware Options Table 177 Option definitions Option Mass mailers to Trojan horses Definition When selected, applies the specified action to this type of malware. If the option is not selected, the malware is handled as described by the basic options. Specific detection name If detected Use the default alert When selected, allows you to add names of specific detections. You can use "*" and "?" to represent multiple and single characters in the malware names. Provides various actions to take. When selected, issues the default alert upon detection. When deselected, allows you to click the link, then change the text of the alert. And also Do not perform custom malware check if the object has already been cleaned Provides further actions to take. When selected, prevents further processing. HTTPS Web Categorization Settings Use this page to block SSL/HTTPS access to specified websites. The address of a secure website has the form: https://www.example.com. Web | Web Policies | Scanning Policies | HTTPS web categorization To determine which sites to block, the appliance refers to its lists of denied URLs. HTTPS filtering might not work as expected. Because the URL (website address) is encrypted, the appliance must resolve the IP address into a name, then match that name against a list of denied URLs. A single IP address often serves many websites. For example, suppose www.example.com and www.mcafee.com resolve to 123.123.123.123. However, the IP address, 123.123.123.123 resolves only to www.mcafee.com. If the list of denied URLs includes www.example.com but does not include www.mcafee.com, the appliance cannot block a secure HTTP connection to 123.123.123.123. McAfee Email and Web Security Appliances 5.6.0 Product Guide 187

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Anti-Virus Settings — Custom Malware Options
Use this page to specify the actions to take when some types of malicious software (“malware”) are
detected.
Email
|
Email Policies
|
Scanning Policies [Anti-virus]
|
Custom Malware Options
Web
|
Web Policies
|
Scanning Policies [Anti-Virus]
|
Custom Malware Options
Table 177
Option definitions
Option
Definition
Mass mailers
to
Trojan horses
When selected, applies the specified action to this type of malware.
If the option is not selected, the malware is handled as described by
the basic options.
Specific detection name
When selected, allows you to add names of specific detections. You
can use “*” and “?” to represent multiple and single characters in the
malware names.
If detected
Provides various actions to take.
Use the default alert
When selected, issues the default alert upon detection.
When deselected, allows you to click the link, then change the text of
the alert.
And also
Provides further actions to take.
Do not perform custom malware
check if the object has already been
cleaned
When selected, prevents further processing.
HTTPS Web Categorization Settings
Use this page to block SSL/HTTPS access to specified websites. The address of a secure website has
Web
|
Web Policies
|
Scanning Policies
|
HTTPS web categorization
To determine which sites to block, the appliance refers to its lists of denied URLs.
HTTPS filtering might not work as expected. Because the URL (website
address) is encrypted, the appliance must resolve the IP address into a
name, then match that name against a list of denied URLs. A single IP
address often serves many websites. For example, suppose
www.example.com and www.mcafee.com resolve to 123.123.123.123.
However, the IP address, 123.123.123.123 resolves only to
www.mcafee.com. If the list of denied URLs includes www.example.com
but does not include www.mcafee.com, the appliance cannot block a
secure HTTP connection to 123.123.123.123.
Overview of Web features
Web Policies
McAfee Email and Web Security Appliances 5.6.0 Product Guide
187