Dynamic Web Content Filtering - D-Link DFL-1660 User Manual

Network security firewall
Hide thumbs Also See for DFL-1660:
Table of Contents

Advertisement

6.3.4. Dynamic Web Content Filtering

4.
Now click Add and select HTTP ALG URL from the menu
5.
Select Blacklist as the Action
6.
Enter */*.exe in the URL textbox
7.
Click OK
Finally, make an exception from the blacklist by creating a whitelist:
1.
Go to: Objects > ALG
2.
In the table, click on the recently created HTTP ALG to view its properties
3.
Click the HTTP URL tab
4.
Now click Add and select HTTP ALG URL from the menu
5.
Select Whitelist as the Action
6.
In the URL textbox, enter www.D-Link.com/*.exe
7.
Click OK
Simply continue adding specific blacklists and whitelists until the filter satisfies the needs.
6.3.4. Dynamic Web Content Filtering
6.3.4.1. Overview
As part of the HTTP ALG, NetDefendOS supports Dynamic Web Content Filtering (WCF) of web
traffic, which enables an administrator to permit or block access to web pages based on the content
type of those web pages.
Dynamic WCF Databases
NetDefendOS Dynamic WCF allows web page blocking to be automated so it is not necessary to
manually specify beforehand which URLs to block or to allow. Instead, D-Link maintains a global
infrastructure of databases containing huge numbers of current web site URL addresses which are
already classified and grouped into a variety of categories such as shopping, news, sport,
adult-oriented and so on.
The Dynamic WCF URL databases are updated almost hourly with new, categorized URLs while at
the same time older, invalid URLs are dropped. The scope of the URLs in the databases is global,
covering websites in many different languages and hosted on servers located in many different
countries.
Note: WCF database access uses TCP port 9998
When NetDefendOS sends a query to the external WCF databases, it sends it as a TCP
request to the destination port 9998.
Therefore, any network equipment through which the request passes, including other
firewalls, must not block TCP traffic with destination port 9998.
If the equipment through which the message passes is another NetDefend Firewall, an
IP rule with the action Allow should be created along with a custom service that is
then associated with the rule.
328
Chapter 6. Security Mechanisms

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Dfl-2560Dfl-2560gDfl-260eDfl-860e

Table of Contents