How to restrict web features in CFS 4.0

Description

Restrict Web Features is available in CFS 3.0, but in CFS 4.0 this feature has been removed. This article will show you how to realize Restrict Web Features after upgrading to CFS 4.0.

Resolution

Restrict Web Features are included with SonicOS. In CFS 3.0 you can select any of the following applications to block:

• ActiveX  • Java  • Cookies  • Access to HTTP Proxy Servers

Image

When you upgrade to CFS 4.0, as these features are removed, you can follow below steps to block these applications.

  • Block ActiveX

1. Go to Firewall | Content Filter Objects | Create an ActiveX URI Object. 

Image

Add an Active X URI Object "*.ocx" at URI List Objects area.

Image

2. Add the Active X URI List Object to the Forbidden URI List of the CFS Profile Object at CFS Profile Objects area

Image

3. Navigate to Security Services | Content Filter page, Create the CFS Policy with the Profile Object you created in step 2.

Image 

  • Block Java

1. Go to Firewall | Content Filter Objects | Create an JAVA URI Object. 

Image

Add an JAVA URI Object "*.jar" and "*.class"at URI List Objects area.

Image

2. Add the JAVA URI List Object to the Forbidden URI List of the CFS Profile Object at CFS Profile Objects area

Image

3. Navigate to Security Services | Content Filter page, Create the CFS Policy with the Profile Object you created in step 2.

Image

  • Block Cookies

1.  Go to Firewall | Content Filter Objects | Edit or Add a CFS Action Objects | Tick the box of option Wipe Cookies

Image

2.  Navigate to Security Services | Content Filter page, Create the CFS Policy with the Action Object you created in step 1.

Image

  • Block Access to HTTP Proxy Servers

Note: to block HTTP Proxy Servers, you should have your License for App Rules ready. 

1. Navigate to Firewall | App Control Advanced page, Enable App Control at App Control Global Settings area.

Image

Image

2. Select PROXCY-ACCESS for Category and HTTP Proxy for Application at App Control Advanced area | Click Configure button for HTTP Proxy Application. 

Image

3. Select Enable for option Block in the pop-up App Control App Settings window | Click button OK.

Image

Related Articles

  • SSH password authentication fails after OpenSSH upgrade
    Read More
  • Where can I download SonicWall stencils?
    Read More
  • Configuring High Availability Monitoring settings
    Read More
not finding your answers?