Webfilter

From Wiki of WFilter NG Firewall
(Difference between revisions)
Jump to: navigation, search
(Utils)
Line 1: Line 1:
==Black&White List==
+
{{DISPLAYTITLE:Web Filter}}
'''White List''': When white list is enabled, only messenger ids in the white list are available.<br>
+
== Web Filter ==
e.g. Block Internet except 'www.imfirewall.com'.<br>
+
The "Web Filter" module has below features:
 +
* Website black & white list
 +
* Website category filtering
 +
* File type and content type filtering
 +
* Other features like limiting downloading size, blocking web access via IP...
 +
 
 +
Please notice, enterprise license is required to enable "category blocking".
 +
 
 +
* Each client can be applied with multiple policies.
 +
* Every policy can set "applied to" "clients" and "effective time".
 +
* Besides the applied to "clients" and "time", detailed "web filter policy" settings are described in below.
 +
 
 +
== Website Black & White List ==
 +
 
 +
* Wildcards "*?" are supported.
 +
* By default, black & white list is applied to both http and https websites.
 +
* You may starts a comment with '#'.
 +
 
 +
* '''White List''': When enabled, only domains in the white list can be accessed, all others will be blocked.
 +
For example, enable "white list" and add "*.imfirewall.com" into the list, network users are only allowed to visit pages from imfirewall.com.
 +
 
 
[[File:Faq_en_webfilter001.jpg]]
 
[[File:Faq_en_webfilter001.jpg]]
<p>Now Internet is blocked but you can visit www.imfirewall.com or wiki.imfirewall.com.</p>
+
 
'''Black List''': When black list is enabled, all black-listed ids will be blocked.
+
* '''Black List''': When enabled, only domains in the black list will be blocked, all others will be allowed.
e.g. Block shopping website list Taobao.
+
For example, to block youtube during working hours, you can enable "black list" and add "*.youtube.com" into the list.
 +
 
 
[[File:Faq_en_webfilter002.jpg]]
 
[[File:Faq_en_webfilter002.jpg]]
<p>When you visit www.taobao.com it was blocked.</p>
 
  
==Category==
+
== Category Blocking ==
'Categorie' allows you to customize which categories of sites will be blocked. Categories that are blocked will display a block page to the user. You should check 'Apply this rule to https websites' in 'Utils' to apply to https websites.<br>
+
When enabled, you may filter domains by 60+ website categories.
e.g. Block all categories except 'Online Storage'.<br>
+
For example, to save bandwidth, you can set "Streaming Media" to be blocked during working hours. So all video websites will be blocked. "Category Blocking" is applied to both http and https websites by default.
[[File:Faq_en_webfilter003.jpg]]
+
 
<p>Now Internet is blocked but you can visit online storage website like 'https://www.dropbox.com/'</p>
+
[[File:Faq_en_webfilter003.png|600px]]
 +
 
 +
To check a domain's category, you can test "URL Access" in "Utils"->"Policy Testing".
 +
 
 +
[[File:Faq_en_webfilter003_2.png|600px]]
 +
 
 +
== File Filtering ==
 +
 
 +
You can block files by file extensions and HTTP content-type(mime type).  
 +
For example, to block all online video and video file downloading, you can set "Video" to "Deny".  
 +
 
 +
[[File:Faq_en_webfilter005.jpg|600px]]
 +
 
 +
Please notice:
 +
* To customize file types, you may click the "edit" icon besides every file type.
 +
* File filtering is only applied to http websites.
 +
 
 +
[[File:Faq_en_webfilter004.jpg|600px]]
 +
 
 +
== Exception ==
 +
 
 +
Domains in the exception list will not be blocked by other options within this policy. For example, you may block "*.yahoo.com" but add "sports.yahoo.com" to the exception list. In result of allowing access to "sports.yahoo.com", while all other domains from yahoo.com will be blocked.
 +
 
 +
[[File:Faq_en_webfilter006.jpg]]
  
==Files==
+
[[File:Faq_en_webfilter007.jpg]]
'Files' allows you to block files by file extension. You can customize file extension in every file type.<br>
+
e.g. Edit 'Video' file type:<br>
+
[[File:Faq_en_webfilter004.jpg]]
+
<p>e.g. Block 'Video' and 'Audio':</p>
+
[[File:Faq_en_webfilter005.jpg]]
+
<p>Now you download a mp3 or video in web, it was blocked.</p>
+
  
==Exception==
+
== Utils ==
Domains in exception list aren't block, exception's priority is highest.<br>
+
* '''Apply this rule to https websites''': apply the "white & black list" and "category blocking" to https sites, enabled by default.
e.g. Block Yahoo except sport in Yahoo, you can block '*.yahoo.com' in 'Black List' and add 'sports.yahoo.com' in Exception:<br>
+
* '''Block web surfing via IP''': when enabled, websites can only be visited via domains.
[[File:Faq_en_webfilter006.jpg]]&nbsp;&nbsp;&nbsp;&nbsp;[[File:Faq_en_webfilter007.jpg]]
+
* '''Block web downloading when file exceeds xx(MB)''': this option is valid to http sites only.
<p>Now you visit sports.yahoo.com, it's OK; visit www.yahoo.com, it's blocked.</p>
+
* '''Blocking Behavior''', when a http webpage is blocked, you may choose to display a blocking page(defined in "System"->"Denial Page"), or redirect to another URL.
  
==Utils==
+
[[File:Faq_en_webfilter008.jpg|600px]]
<p>1. 勾选“'''对https站点也启用黑白名单和网页分类过滤'''”,在黑白名单和网页分类中配置的规则对https网址也生效,默认该项是选中的。<br>
+
例如:在网站黑名单中配置了“*.baidu.com”,勾选该项。访问http://www.baidu.com和https://www.baidu.com,都被禁止。</p>
+
<p>2. 勾选“'''禁止通过IP访问'''”,访问网页时只能通过域名来访问。<br>
+
例如:启用该项后,访问www.baidu.com正常,访问180.97.33.107则无法打开百度首页。</p>
+
<p>3. 勾选“'''禁止Web文件'''”后可以定义web文件下载的大小。'''请注意:该项只能对http网址起作用'''<br>
+
例如:公司禁止下载大小超过2M的Web文件。打开网页下载一首歌曲,无法下载。</p>
+
<p>4. '''被封堵时'''可以选择显示封堵提示页面(页面内容在“系统配置-封堵提示”中配置),也可以重定向到某个网址。<br>
+
例如:当员工访问被禁止的网址时,显示封堵页面,提示员工“不要在上班时间访问不相关网站”。</p>
+
[[File:Faq_en_webfilter008.jpg]]
+
  
==FAQ==
+
== FAQ ==

Revision as of 11:45, 23 December 2015

Contents

1 Web Filter

The "Web Filter" module has below features:

  • Website black & white list
  • Website category filtering
  • File type and content type filtering
  • Other features like limiting downloading size, blocking web access via IP...

Please notice, enterprise license is required to enable "category blocking".

  • Each client can be applied with multiple policies.
  • Every policy can set "applied to" "clients" and "effective time".
  • Besides the applied to "clients" and "time", detailed "web filter policy" settings are described in below.

2 Website Black & White List

  • Wildcards "*?" are supported.
  • By default, black & white list is applied to both http and https websites.
  • You may starts a comment with '#'.
  • White List: When enabled, only domains in the white list can be accessed, all others will be blocked.

For example, enable "white list" and add "*.imfirewall.com" into the list, network users are only allowed to visit pages from imfirewall.com.

Faq en webfilter001.jpg

  • Black List: When enabled, only domains in the black list will be blocked, all others will be allowed.

For example, to block youtube during working hours, you can enable "black list" and add "*.youtube.com" into the list.

Faq en webfilter002.jpg

3 Category Blocking

When enabled, you may filter domains by 60+ website categories. For example, to save bandwidth, you can set "Streaming Media" to be blocked during working hours. So all video websites will be blocked. "Category Blocking" is applied to both http and https websites by default.

600px

To check a domain's category, you can test "URL Access" in "Utils"->"Policy Testing".

Faq en webfilter003 2.png

4 File Filtering

You can block files by file extensions and HTTP content-type(mime type). For example, to block all online video and video file downloading, you can set "Video" to "Deny".

Faq en webfilter005.jpg

Please notice:

  • To customize file types, you may click the "edit" icon besides every file type.
  • File filtering is only applied to http websites.

Faq en webfilter004.jpg

5 Exception

Domains in the exception list will not be blocked by other options within this policy. For example, you may block "*.yahoo.com" but add "sports.yahoo.com" to the exception list. In result of allowing access to "sports.yahoo.com", while all other domains from yahoo.com will be blocked.

Faq en webfilter006.jpg

Faq en webfilter007.jpg

6 Utils

  • Apply this rule to https websites: apply the "white & black list" and "category blocking" to https sites, enabled by default.
  • Block web surfing via IP: when enabled, websites can only be visited via domains.
  • Block web downloading when file exceeds xx(MB): this option is valid to http sites only.
  • Blocking Behavior, when a http webpage is blocked, you may choose to display a blocking page(defined in "System"->"Denial Page"), or redirect to another URL.

Faq en webfilter008.jpg

7 FAQ

Personal tools
Namespaces

Variants
Actions
Navigation
Tools