3Com Switch 8800 Family Firewall Module Configuration and Command Reference Guide

136 CHAPTER 9: WEB AND E-MAIL FILTERING
Configuring Web
Content Filtering
Enabling/Disabling Web content filtering
Before configuring Web content filtering for a firewall, you must enable this
function first for related configurations to take effect.
Perform the following configuration in system view.
Web content filtering is disabled by default.
c
CAUTION: You must configure ASPF policies and execute the detect http and
detect tcp commands first to enable Web content filtering. Refer to section
“Configuring ASPF” “Configuring ASPF” for information about ASPF.
Configuring a filtering keyword for Web content filtering
Web pages can be filtered according to the filtering keyword items previously
configured in a Web content filtering file. The administrator can manipulate this
kind of files to add or delete Web content filtering keywords in them, or even clear
all the Web content filtering keywords.
Perform the following configuration in system view.
c
CAUTION: The new Web content filtering keyword cannot be an HTML tag such
as <head>, <html>, <title> and <script>. Otherwise, valid web pages may be
filtered.
Saving/Loading a Web content filtering file
After configuring the Web content filtering keywords, you can save them to a
Web content filtering file for later use. You must load a Web content filtering file
first to configure or modify items in it.
Perform the following configuration in system view.
Tabl e 127 Enable Web content filtering
Operation Command
Enable Web content filtering firewall webdata-filter enable
Disable Web content filtering undo firewall webdata-filter enable
Tabl e 128 Configure a filtering keyword for Web content filtering
Operation Command
Add a Web content filtering keyword firewall webdata-filter add keywords
Delete a Web content filtering keyword firewall webdata-filter delete keywords
Clear all Web content filtering keywords firewall webdata-filter clear
Tabl e 129 Save /Load a Web content filtering file
Operation Command
Save /Load a Web content filtering file
firewall webdata-filter { save-file |
load-file } file-name
Unload the current Web content filtering file undo firewall webdata-filter load-file