HP 7102dl - ProCurve Secure Router Configuration Manual page 337

Procurve secure router 7000dl series - advanced management and configuration guide
Hide thumbs Also See for 7102dl - ProCurve Secure Router:
Table of Contents

Advertisement

denied through the ProCurve Secure Router operating system (OS). The
router then automatically passes traffic associated with the permitted
domains and blocks traffic associated with the denied domains. (Note that
you must still apply a filter to an interface in order for exclusive domains to
take effect.)
Because the router allows or denies access to the exclusive domains without
ever contacting the Websense server, the policy set by the ip urlfilter exclu-
sive-domain command necessarily supersedes any policy set on the Web-
sense server.
You might be tempted to use the ip urlfilter exclusive-domain command to
override the way the Websense master database classifies a certain URL. Such
a use is legitimate; however, it is often a better idea to use the Websense
Manager for this function because the policy is then applied consistently
throughout your network to the correct users and at the correct times. (To
learn how to configure Custom URLs, download the "Websense Enterprise
Administrator's Guide" from http://www.websense.com/global/en/Sup-
portAndKB/ProductDocumentation.)
Instead of using the exclusive domain feature to override Websense decisions,
you can use it to:
speed processing for frequently accessed Web sites
ensure that certain Web sites remain accessible even if the router loses
contact with the Websense server and has disabled Allow mode
ensure that certain Web sites remain blocked even if the router loses
contact with the Websense server and has enabled Allow mode
All Web pages associated with the exclusive domain are permitted or denied
as you specify in the command. However, some Web sites include sections
that use different domain names; these will be unaffected by the command.
Always be careful when setting up exclusive domains: you risk having policies
that do not take effect as you anticipate. For example, many Web sites can be
accessed through multiple domain names. You could deny one domain name
only to have users access the site through another. On the other hand, you
might attempt to permit a domain name, but users find that they cannot access
portions of the Web Site because that domain name actually redirects clients
to a different domain. Make sure to add both the domain names.
To specify a fully qualified domain name (FQDN) that users can always
access, enter this command from the global configuration mode context:
Syntax: ip urlfilter exclusive-domain permit <FQDN>
Content Filtering
Configuring Web Content Filtering
7-9

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7203dl j8753a j8753a

Table of Contents