Kerio Tech Firewall6 User Manual

Page 158

Advertising
background image

Chapter 12

HTTP and FTP filtering

158

for example a rule allowing access to certain pages without authentication

can be defined.

2.

Unless authentication is required, the do not require authentication option is

ineffective.

selected user(s) — applied on selected users or/and user groups.

Click on the Set button to select users or groups (hold the Ctrl and the Shift keys

to select more that one user /group at once).

Note: In rules, username represents IP address of the host fro which the user is

currently connected to the firewall (for details, see chapter

10.1

).

And URL matches criteria

Specification of URL (or URL group) on which this rule will be applied:

URL begins with — this item can include either entire URL

(i.e. www.kerio.com/index.html) or only a substring of a URL using an asterisk

(wildcard matching) to substitute any number of characters (i.e. *.kerio.com*)
Server names represent any URL at a corresponding server (www.kerio.com/*).

is in URL group — selection of a URL group (refer to chapter

14.4

) which the URL

should match with

is rated by ISS OrangeWeb Filter rating system — the rule will be applied on all

pages matched with a selected category by the ISS OrangeWeb Filter plug-in (see

chapter

12.4

).

Click on the Select Rating... button to select from ISS OrangeWeb Filter categories.

For details, refer to chapter

12.4

.

is any URL where server is given as IP address — by enabling this option users

will not be able to bypass URL based filters by connecting to Web sites by IP

address rather than domain name. This trick is often used by servers offering

illegal downloads.

Warning

If access to servers specified by IP addresses is not denied, users can bypass URL

rules where servers are specified by names.

Action

Selection of an action that will be taken whenever a user accesses a URL meeting a rule:

Allow access to the Web site

Deny access to the Web site — requested page will be blocked. The user will be

informed that the access is denied or a blank page will be displayed (according

to settings in the Advanced tab — see below).

Tick the Log option to log all pages meeting this rule in the Filter log (see chapter

22.9

).

Advertising