Content filtering configuration example, Network requirements – H3C Technologies H3C SecPath F1000-E User Manual

Page 85

Advertising
background image

77

Figure 79 Statistic information

Content filtering configuration example

Network requirements

As shown in

Figure 80

, hosts in LAN segment 192.168.1.0/24 access the Internet through SecPath.

Security zones Trust and Untrust are configured on SecPath for the LAN and the Internet respectively.
Perform the following configurations on SecPath:

Enable HTTP body filtering to block HTTP responses that carry keyword abc.

Enable HTTP Java applet blocking to block Java applet requests to all websites except the one with
IP address 5.5.5.5.

Enable SMTP attachment name filtering to block all emails that carry .exe attachments.

Enable FTP upload filename filtering to prevent users from uploading files that carry abc in the
filenames.

Enable Telnet command word filtering to prevent users from executing commands that carry the
command keyword reboot.

Advertising