Symantec 360R Administration Guide - Page 111

About content filtering, Special considerations

Page 111 highlights

Advanced network traffic control 111 About content filtering If this message is present, then your AVpe feature is correctly configured and operational. 5 If you are able to connect to www.symantec.com, recheck your AVpe configuration settings and group assignments. Make sure that you uninstalled Symantec AntiVirus Corporate Edition from the client workstation, and that the client is a member of group with AVpe enabled, with connections blocked. Retry steps 1 through 4 above. About content filtering Symantec Gateway Security 300 Series supports basic content filtering for outbound traffic. You use content filtering to restrict the content to which clients have access. For example, to restrict your users from seeing gambling sites, you configure content filtering to deny access to gambling URLs that you specify. Content filtering is administered through computer groups and VPN groups. A computer group is a group of computers defined in the Firewall section to which you apply the same rules. Similarly, a VPN group is a group of VPN users defined in the VPN section to which you apply the same rules. When you define a computer group, you specify if the group uses a content filtering deny or allow list. Deny lists (black lists) block internal access to sites on the list and allows all others sites. Allow lists (white lists) permit internal access to sites on the list, and blocks access to all other sites. Note: By default, content filtering is disabled for all computer groups. The allow list permits traffic to pass to sites that exactly match entries in the list. The content filtering engine drops connection requests sent to a destination that do not match the entries in the list. If the allow list is empty, all traffic is blocked. If the deny list is empty, traffic is not filtered. Once entries are added to the deny list, the content filtering engine drops connection requests sent to a destination that exactly matches an entry. Traffic that does not match an entry is allowed to pass. Special considerations When content filtering and AVpe are concurrently enabled, content filtering is performed first. If the content filtering results in a blocked connection, AVpe is not processed; only a content filtering message is logged.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

111
Advanced network traffic control
About content filtering
If this message is present, then your AVpe feature is correctly configured
and operational.
5
If you are able to connect to www.symantec.com, recheck your AVpe
configuration settings and group assignments. Make sure that you
uninstalled Symantec AntiVirus Corporate Edition from the client
workstation, and that the client is a member of group with AVpe enabled,
with connections blocked. Retry steps 1 through 4 above.
About content filtering
Symantec Gateway Security 300 Series supports basic content filtering for
outbound traffic. You use content filtering to restrict the content to which
clients have access. For example, to restrict your users from seeing gambling
sites, you configure content filtering to deny access to gambling URLs that you
specify.
Content filtering is administered through computer groups and VPN groups. A
computer group is a group of computers defined in the Firewall section to which
you apply the same rules. Similarly, a VPN group is a group of VPN users defined
in the VPN section to which you apply the same rules. When you define a
computer group, you specify if the group uses a content filtering deny or allow
list. Deny lists (black lists) block internal access to sites on the list and allows all
others sites. Allow lists (white lists) permit internal access to sites on the list,
and blocks access to all other sites.
Note:
By default, content filtering is disabled for all computer groups.
The allow list permits traffic to pass to sites that exactly match entries in the
list. The content filtering engine drops connection requests sent to a destination
that do not match the entries in the list. If the allow list is empty, all traffic is
blocked.
If the deny list is empty, traffic is not filtered. Once entries are added to the deny
list, the content filtering engine drops connection requests sent to a destination
that exactly matches an entry. Traffic that does not match an entry is allowed to
pass.
Special considerations
When content filtering and AVpe are concurrently enabled, content filtering is
performed first. If the content filtering results in a blocked connection, AVpe is
not processed; only a content filtering message is logged.