HP VPN Firewall Appliances Attack Protection Configuration Guide
168
Item Descri
p
tion
IP List
Configure IP addresses that the URL filtering policy will filter.
You may configure a maximum of 10 IP addresses, including host addresses
and network segment addresses.
NOTE:
Only IP addresses of the destination domain are configured in this field.
Excluded IP List
Configure IP addresses that the URL filtering policy will not filter.
You may configure a maximum of 10 IP addresses, including host addresses
and network segment addresses.
NOTE:
Only IP addresses configured in the IP List field can be specified as the
excluded IP addresses.
Advanced security prevention configuration
example
Feature and hardware compatibility
Hardware Confi
g
uration exam
p
le com
p
atibilit
y
F1000-A-EI/F1000-E-SI/F1000-S-AI Yes
F1000-C-G/F1000-S-G/F1000-A-G Yes
F1000-E No
F1000-S-EI No
F100-C-G/F100-S-G Yes
F100-M-G/F100-A-G/F100-E-G Yes
F5000-A5 No
F5000-S/F5000-C No
Firewall modules No
U200-A/U200-M/U200-CA Yes
U200-S/U200-CS/U200-CM Yes
Network requirements
As shown in Figure 148, the internal network of the enterprise is connected to the Internet through the
firewall. Configure the firewall to protect the enterprise's internal network as follows:
• Block and log critical-level attacks from the Internet.
• Block and log traffic from the Internet that carries viruses or is abnormal.
• Monitor QQ and MSN applications of the internal users every Monday to Friday.