Guardian Status Filtering
Total Page:16
File Type:pdf, Size:1020Kb
Secure Web Gateway Network Guardian – Administrator’s Guide Smoothwall® Network Guardian, Administrator’s Guide, May 2013 Smoothwall publishes this guide in its present form without any guarantees. This guide replaces any other guides delivered with earlier versions of Network Guardian. No part of this document may be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without the express written permission of Smoothwall. For more information, contact: [email protected] © 2001 – 2013 Smoothwall Ltd. All rights reserved. Trademark notice Smoothwall and the Smoothwall logo are registered trademarks of Smoothwall Ltd. Linux is a registered trademark of Linus Torvalds. Snort is a registered trademark of Sourcefire INC. DansGuardian is a registered trademark of Daniel Barron. Microsoft, Internet Explorer, Window 95, Windows 98, Windows NT, Windows 2000 and Windows XP are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. Netscape is a registered trademark of Netscape Communications Corporation in the United States and other countries. Apple and Mac are registered trademarks of Apple Computer Inc. Intel is a registered trademark of Intel Corporation. Core is a trademark of Intel Corporation. All other products, services, companies, events and publications mentioned in this document, associated documents and in Smoothwall software may be trademarks, registered trademarks or service marks of their respective owners in the UK, US and/or other countries. Acknowledgements Smoothwall acknowledges the work, effort and talent of the Smoothwall GPL development team: Lawrence Manning and Gordon Allan, William Anderson, Jan Erik Askildt, Daniel Barron, Emma Bickley, Imran Chaudhry, Alex Collins, Dan Cuthbert, Bob Dunlop, Moira Dunne, Nigel Fenton, Mathew Frank, Dan Goscomb, Pete Guyan, Nick Haddock, Alan Hourihane, Martin Houston, Steve Hughes, Eric S. Johansson, Stephen L. Jones, Toni Kuokkanen, Luc Larochelle, Osmar Lioi, Richard Morrell, Piere-Yves Paulus, John Payne, Martin Pot, Stanford T. Prescott, Ralf Quint, Guy Reynolds, Kieran Reynolds, Paul Richards, Chris Ross, Scott Sanders, Emil Schweickerdt, Paul Tansom, Darren Taylor, Hilton Travis, Jez Tucker, Bill Ward, Rebecca Ward, Lucien Wells, Adam Wilkinson, Simon Wood, Nick Woodruffe, Marc Wormgoor. Network Guardian contains graphics taken from the Open Icon Library project http:// openiconlibrary.sourceforge.net/ Address Smoothwall Limited 1 John Charles Way Leeds. LS12 6QA United Kingdom Email [email protected] Web www.smoothwall.net Telephone USA and Canada: 1 800 959 3760 United Kingdom: 0870 1 999 500 All other countries: +44 870 1 999 500 Fax USA and Canada: 1 888 899 9164 United Kingdom: 0870 1 991 399 All other countries: +44 870 1 991 399 Contents Chapter 1 Introduction .................................................... 1 Overview of Network Guardian........................................................ 1 Who should read this guide? ........................................................... 1 Other User Information..................................................................... 1 Support .............................................................................................. 1 Chapter 2 Network Guardian Overview......................... 3 Accessing Network Guardian .......................................................... 3 Dashboard ......................................................................................... 4 Logs and reports............................................................................... 4 Networking ........................................................................................ 6 Services.............................................................................................. 7 System ............................................................................................... 8 Guardian........................................................................................... 11 Swurl ................................................................................................ 13 Web Proxy........................................................................................ 13 Email................................................................................................. 14 Configuration Guidelines................................................................ 15 Connecting via the Console........................................................... 17 Secure Communication.................................................................. 18 Chapter 3 Working with Interfaces .............................. 19 Managing Network Interfaces ....................................................... 19 Changing the IP Address................................................................ 20 Chapter 4 Deploying Web Filtering .............................. 21 Getting Up and Running ................................................................. 21 About Network Guardian’s Default Policies ................................. 24 Chapter 5 Working with Policies .................................. 27 An Overview of Policies.................................................................. 27 Working with Category Group Objects......................................... 30 Working with Time Slot Objects .................................................... 34 Working with Location Objects ..................................................... 35 Working with Quota Objects.......................................................... 36 Managing Web Filter Policies ........................................................ 38 Managing HTTPS Inspection Policies........................................... 42 Managing Content Modification Policies...................................... 47 Managing Anti-malware Policies................................................... 50 Working with Policy Folders .......................................................... 54 Censoring Web Form Content ....................................................... 55 Configuring Organization Accounts.............................................. 58 Chapter 6 Managing Authentication Policies.............. 61 3 About Authentication Policies ....................................................... 61 Creating Authentication Policies ................................................... 61 Managing Authentication Policies................................................. 70 Managing Authentication Exceptions ........................................... 71 Identification by Location............................................................... 71 Connecting to Network Guardian.................................................. 72 Authentication Scenarios ............................................................... 74 Chapter 7 Managing Web Security .............................. 77 Overview of the Web Proxy............................................................ 77 Using PAC Scripts........................................................................... 81 Limiting Bandwidth Use ................................................................. 84 Configuring WCCP.......................................................................... 86 Managing Upstream Proxies ......................................................... 87 Managing Blocklists ....................................................................... 94 Managing Block Pages................................................................... 95 Chapter 8 Guardian Alerts, Logs and Reports.......... 103 About Alerts................................................................................... 103 Realtime Web Filter Information.................................................. 105 Web Filter Logs ............................................................................. 106 Guardian Reports.......................................................................... 108 Chapter 9 Working with MobileProxy ........................ 109 About MobileProxy........................................................................ 109 Managing MobileProxy Server Keys ........................................... 113 Chapter 10 Managing Your Network Infrastructure... 115 Creating Subnets .......................................................................... 115 Using RIP ....................................................................................... 116 Managing Internal Aliases............................................................ 118 Chapter 11 General Network Security Settings.......... 121 Blocking by IP................................................................................ 121 Configuring Advanced Networking Features ............................. 123 Working with Port Groups............................................................ 125 Chapter 12 Configuring Inter-Zone Security............... 129 About Zone Bridging Rules .......................................................... 129 Creating a Zone Bridging Rule .................................................... 129 Editing and Removing Zone Bridge Rules.................................. 130 A Zone Bridging Tutorial .............................................................. 131 Group Bridging .............................................................................. 132 Chapter 13 Network Guardian Services ...................... 135 Working with User Portals ..........................................................