As shown in
This configuration example was created and verified on R9900P25 of the M9000-X06 device.
Data filtering supports filtering packets of the following protocols:
HTTP.
FTP.
SMTP.
IMAP.
NFS.
POP3.
RTMP.
SMB.
For data filtering to inspect HTTPS protocol packets, you must also configure the application proxy feature. To configure the application proxy feature, access the
Assign IP addresses to interfaces and add the interfaces to security zones:
# On the top navigation bar, click
# From the navigation pane, select
# Click the
# In the dialog box that opens, configure the interface:
Select the
Click the
Click OK.
# Add GE 1/0/2 to the
Configure a route:
This example configures a static route. If dynamic routes are required, configure a dynamic routing protocol.
Configure the next hop IP address to reach the external Web server according to the actual network conditions. In this example, the next hop IP address is 20.1.1.2.
To configure a static route:
# On the top navigation bar, click
# From the navigation pane, select
# On the
# In the dialog box that opens, create an IPv4 static route:
Enter destination address
Enter mask length
Enter next hop address
# Click
Configure keyword groups.
# Create keyword group
On the top navigation bar, click
From the navigation pane, select
Click
In the dialog box that opens, configure the keyword group:
Enter
In the
In the
Click
Figure-2 Creating a keyword
The newly created keyword
Figure-3 Creating keyword group
Click
# Create keyword group
On the
In the dialog box that opens, configure the keyword group:
Enter
In the
In the
Click
Figure-4 Creating a keyword
The newly created keyword
Figure-5 Creating keyword group
Click
Configure a data filtering profile.
# On the top navigation bar, click
# From the navigation pane, select
# Click
# In the dialog box that opens, configure a data filtering profile.
Enter the name
In the
In the dialog box that opens, create data filtering rule
Figure-6 Creating data filtering rule rule1
Create data filtering rule
Figure-7 Creating data filtering rule rule2
The data filtering rules are displayed in the
Click
Figure-8 Creating a data filtering profile
Create a security policy:
# On the top navigation bar, click
# From the navigation pane, select Security Policies > Security Policies.
# Click Create.
# In the dialog box that opens, configure a security policy:
Enter policy name
Select type
Select source zone
Select destination zone
Select source IP address
Select action
Select data filtering profile
# Click
Enable logging:
# On the top navigation bar, click
# From the navigation pane, select
# Select
Verify that data filtering can log and block the following Internet access behaviors of internal users:
Browsing, publishing, or downloading information containing the
Transferring files marked as for internal use only on the Internet.
To view the logs generated for these behaviors, perform either of the following tasks:
At the CLI, execute the
On the Web interface, click