Symantec 360R Administration Guide - Page 112

Managing content filtering lists, Special considerations

Page 112 highlights

112 Advanced network traffic control Managing content filtering lists If you make changes to content filtering on the appliance, clear the DNS and browser caches on the client machine. If a URL is accessed by a client, but then the content filtering settings change to deny access to that URL, the cache may be used and allow the client access to the URL. Refer to your operating system documentation for information on clearing DNS caches and your browser's documentation for clearing the browser cache. If you enable content filtering for remote WAN-side VPN clients, you must have DNS servers on the local LAN. Managing content filtering lists When you create allow and deny lists, you provide the allowed or denied fully qualified domain names. The appliance filters traffic by checking DNS lookup requests. There must be an exact match on the destination for action (blocking or warning) to occur. For wild card functionality, specify only the domain name in the allow or deny list for specific sites. For example, to allow traffic to any Symantec site, add symantec.com to the allow list. This allows traffic to liveupdate.symantec.com, www.symantec.com, fileshare.symantec.com, and so on. Content filtering applies to all outbound traffic, not just HTTP (Web) traffic. Special considerations If a site or security gateway uses redirection to transfer users from one URL to another, you must include both URLs in the list. For example, www.disney.com redirects users to www.disney.go.com. To allow your users to view this Web site, you must specify both www.disney.com and www.disney.go.com in the allow list. If a site brings in content from other sites, you must add both URLs to the list. For example, www.cnn.com uses content from www.cnn.net. To manage allow and deny lists By default, the allow and deny lists are empty. Each filtering list can hold up to 100 entries. Each entry can be up to 128 characters long. See "Content filtering field descriptions" on page 210. To add a URL to an allow or deny list 1 In the left pane, click Content Filtering. 2 Under Select List, next to List Type, select Allow or Deny.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

112
Advanced network traffic control
Managing content filtering lists
If you make changes to content filtering on the appliance, clear the DNS and
browser caches on the client machine. If a URL is accessed by a client, but then
the content filtering settings change to deny access to that URL, the cache may
be used and allow the client access to the URL. Refer to your operating system
documentation for information on clearing DNS caches and your browser’s
documentation for clearing the browser cache.
If you enable content filtering for remote WAN-side VPN clients, you must have
DNS servers on the local LAN.
Managing content filtering lists
When you create allow and deny lists, you provide the allowed or denied fully
qualified domain names. The appliance filters traffic by checking DNS lookup
requests. There must be an exact match on the destination for action (blocking
or warning) to occur.
For wild card functionality, specify only the domain name in the allow or deny
list for specific sites. For example, to allow traffic to any Symantec site, add
symantec.com to the allow list. This allows traffic to liveupdate.symantec.com,
www.symantec.com, fileshare.symantec.com, and so on.
Content filtering applies to all outbound traffic, not just HTTP (Web) traffic.
Special considerations
If a site or security gateway uses redirection to transfer users from one URL to
another, you must include both URLs in the list. For example, www.disney.com
redirects users to www.disney.go.com. To allow your users to view this Web site,
you must specify both www.disney.com and www.disney.go.com in the allow list.
If a site brings in content from other sites, you must add both URLs to the list.
For example, www.cnn.com uses content from www.cnn.net.
To manage allow and deny lists
By default, the allow and deny lists are empty. Each filtering list can hold up to
100 entries. Each entry can be up to 128 characters long.
See
“Content filtering field descriptions”
on page 210.
To add a URL to an allow or deny list
1
In the left pane, click
Content Filtering
.
2
Under Select List, next to List Type, select
Allow
or
Deny
.