18-16
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 18 Managing Firewall Web Filter Rules
Configuring Settings for Web Filter Servers
IOS devices—The most interesting setting is Allow Traffic when Servers Unreachable, which
determines whether you allow any web connections if the filtering servers are unavailable. If you do
not select this option, all web traffic is cut off if the servers go offline for any reason.
The remaining settings configure logging and cache size options.
ASA, PIX, FWSM devices—These options configure the cache size and buffer limits used with the
filtering servers. You can also control whether the cached responses include both source and
destination (if you have different filtering policies per user) or destination only (one policy for all),
as configured in the filtering server.
Web Filter Settings Page
Use the Web Filter settings page to configure the web filter servers and other settings to use with your
web filter rules policy.
You must install and configure the web filter servers as directed by the documentation for the server
before configuring and deploying this policy. Security Manager cannot confirm that the servers exist or
that they are configured correctly.
Tip These settings work only with the web filter rules policy. The web servers you configure here are not
used with zone based firewall rules policies that configure web content filtering.
Navigation Path
To access the Web Filter settings page, do one of the following:
(Device view) Select a device, then select Firewall > Settings > Web Filter from the Policy
selector.
(Policy view) Select Firewall > Settings > Web Filter from the Policy Type selector. Create a new
policy or select an existing one.
(Map view) Right-click a device and select Edit Firewall Settings > Web Filter.
Related Topics
Understanding Web Filter Rules, page18-1
Configuring Settings for Web Filter Servers, page18-15
Configuring Web Filter Rules for ASA, PIX, and FWSM Devices, page 18-2
Configuring Web Filter Rules for IOS Devices, page18-10