Configuring the WebBlocker service

Logging and WebBlocker

WebBlocker logs attempts to access sites blocked by WebBlocker. The log that is generated displays information about source and destination address as well as the blocked URL and the category that caused the denial.

WebBlocker also generates a log entry showing the results of any attempted database retrieval, including whether or not it was successful and, if not successful, why.

Prerequisites to using WebBlocker

You need to complete several tasks before you can configure the Firebox to use WebBlocker:

• Configure the WatchGuard service icon

Because WebBlocker relies on copying updated versions of the WebBlocker database to the Event Processor, you must configure the WatchGuard service setting Allow Outgoing to Any. It is possible to narrow this setting and use the IP address of webblocker.watchguard.com. However, this address may change without notice.

• Add some form of HTTP service icon

To use WebBlocker, add the Proxied-HTTP, Proxy, or HTTP service. WatchGuard recommends using Proxied-HTTP, which provides filtering on all ports. (HTTP without the Proxy service blocks only on port 80.) WebBlocker takes precedence over other settings in the HTTP or Proxy services. If the HTTP service allows outgoing from Any to Any but WebBlocker settings are set to “Block All URLs,” all Web access is blocked. For information on adding an HTTP proxy service, see “Configuring an HTTP proxy service” on page 55.

Configuring the WebBlocker service

WebBlocker is a built-in feature of the service icons including HTTP, Proxied HTTP, and Proxy. When WebBlocker is installed, five tabs appear in the HTTP service icon dialog box:

WebBlocker Controls

WB: Schedule

WB: Operational Hours

WB: Non-Operational Hours

WB: Exceptions

Activating WebBlocker

To start using WebBlocker, you must activate the feature. WatchGuard recommends enabling the Auto Download option at the same time. This ensures that Event

60

Page 70
Image 70
WatchGuard Technologies FireboxTM System 4.6 manual Configuring the WebBlocker service, Logging and WebBlocker