Cisco Cisco Web Security Appliance S170 사용자 가이드

다운로드
페이지 619
 
17-12
Cisco IronPort AsyncOS 7.7.5 for Web User Guide
Chapter 17      URL Filters
Filtering Transactions Using URL Categories
Step 7
Submit and commit your changes.
Configuring URL Filters for Decryption Policy Groups
You can configure URL filtering for user defined Decryption Policy groups and the global Decryption 
Policy group.
Step 1
Navigate to the Web Security Manager > Decryption Policies page.
Step 2
Click the link in the policies table under the URL Categories column for the policy group you want to 
edit.
Step 3
Optionally, in the Custom URL Category Filtering section, you can add custom URL categories on which 
to take action in this policy:
a.
Click Select Custom Categories.
b.
Choose which custom URL categories to include in this policy and click Apply.
Choose which custom URL categories the URL filtering engine should compare the client request 
against. The URL filtering engine compares client requests against included custom URL 
categories, and ignores excluded custom URL categories. The URL filtering engine compares the 
URL in a client request to included custom URL categories before predefined URL categories. 
The custom URL categories included in the policy appear in the Custom URL Category Filtering 
section.
Step 4
Choose an action for each custom and predefined URL category. 
 describes each action. 
Table 17-4
URL Category Filtering for Decryption Policies 
Action
Description
Use Global 
Setting
Uses the action for this category in the global Decryption Policy group. This is the 
default action for user defined policy groups.
Applies to user defined policy groups only.
When a custom URL category is excluded in the global Decryption Policy, then the 
default action for included custom URL categories in user defined Decryption 
Policies is Monitor instead of Use Global Settings. You cannot choose Use Global 
Settings when a custom URL category is excluded in the global Decryption Policy. 
Pass Through
Passes through the connection between the client and the server without inspecting 
the traffic content. You might want to pass through connections to trusted secure 
sites, such as well known banking and financial institutions.
Monitor
The Web Proxy neither allows nor blocks the request. Instead, it continues to 
evaluate the client request against other policy group control settings, such as web 
reputation filtering.