Barracuda Web Filter Release 3.3
42 Chapter 3: Configuring, Monitoring, and Managing the Barracuda Web Filter
Limitations for HTTPS traffic filtering
When the HTTPS traffic-filtering option is enabled, the following limitations apply:
• If HTTPS access is denied, the user is not presented with a block page because the traffic is
blocked at Layer 3.
• If HTTPS access to a particular domain name is denied, HTTPS access to any subdomain of
that same domain will also be denied for the same users.
• For any filtering policy that is set to Warn, the HTTPS request is Blocked instead.
• For URL pattern filters, only the unencrypted portion of the requested HTTPS URL can be
checked for a match with the specified pattern.
To enable the HTTPS traffic-filtering option
To expand your HTTP filtering policies to include HTTPS filtering, enable the HTTPS Filtering
option in the
BLOCK/ACCEPT > Configuration page.
Note:
Immediately after you enable this option, any client machines that had previously established
an HTTPS session are communicating with an IP address and will not be blocked. In this situation, the
HTTPS Web site IP address remains in the DNS client resolver cache (as well as in the DNS table on
the core router or domain controller) until the DNS request time-to-live (TTL) expires. This can take up
to a day or two, depending upon how the HTTPS sites configure TTL.
Testing Web site access
To determine if a specific Web site is allowed or blocked, based on the filters you set up, go to the
BLOCK/ACCEPT > Browse Test page to perform a URL test.
Enter the URL in the field provided, and click
Go. If the Web site appears in the display area on that
page, then your users will be able to access the site. If you receive a message that the Web site has
been blocked, then your users will not be able to access the site.
It is recommended that you make a list of the sites you want to block and allow, and then use the
Browse Test page to test each URL and verify the filters have been set up correctly.
Comentarios a estos manuales