Configuring Web Filtering For Firewall Rules - Juniper NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide
460
When you copy and paste a rule within a rulebase, NSM automatically creates a new
unique ID for the pasted rule.
You are not required to set a ID for a rule.
NOTE: The NSM GUI ID column now accepts alphabetic as well as numeric
IDs.

Configuring Web Filtering for Firewall Rules

After you create a Web Filtering profile and you have enabled Web Filtering on your device,
you need to bind it to your firewall rule. You need to select one of the following options:
Web Filtering Through SurfControl SCFP/WebSense (Redirect)—With this option, the
security devices sends the first HTTP request in a TCP connection to either a Websense
server or a SurfControl server, enabling you to block or permit access to different web
sites based on their URLs, domain names, and IP addresses.
Web Filtering Through SurfControl CPA (Integrated)—With this option you permit or
block access to a requested website by binding the default ns-profile or custom profile
you created to a firewall rule.
When a profile is bound to the firewall rule, the security device matches the URL in the
incoming HTTP request to the categories in the profile in the following sequence:
Black List
White List
Custom URL Lists
Predefined Web categories
If no custom profile is bound to the firewall rule, the security device uses the default
profile ns-profile. If the security device does not find the category of the requested URL,
then it performs the default action, to permit access to the URL (unless otherwise
configured).
In this example, you will bind the predefined Web Filtering profile to a firewall rule.
Click Policies in the navigation tree. Select the device you want to bind to the Web
1.
filter profile.
In the Zone based Firewall Rules main display area, right-click under Rule Options. A
2.
pull-down menu appears.
Select Web Filtering.
3.
In the Edit Web filter dialog box, click Enable.
4.
Select Web Filtering Through SurfControl CPA (Integrated). The Select SC-CPA
5.
Profile box appears.
Select the profile ns_profile to bind to the firewall rule.
6.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.4

Table of Contents