Configuring policies for Internet applications

Article:HOWTO54136  |  Created: 2011-06-08  |  Updated: 2011-06-08  |  Article URL http://www.symantec.com/docs/HOWTO54136
Article Type
How To


Environment

Subject


Configuring policies for Internet applications

Symantec Web Gateway can allow, block, or monitor Internet access for applications with the application control policy settings. For example, you can prevent peer-to-peer sharing, streaming media, and Internet-dependent games from accessing the Internet for some or all computers in your network. You can configure access by category or by the specific programs that are known to Symantec Web Gateway.

All application control settings are available for inline and inline plus proxy mode. However, there are some limitations for proxy only and port tap/span operating modes.

See About policies.

See Internet applications, malware, and URL filtering blocking behavior.

Note:

You must enable the application control module to monitor or block applications.

See Enabling URL filtering, Internet program monitoring, and other features.

Symantec Web Gateway contains network signatures for a large number of commonly used Internet applications. However, you cannot monitor or block any Internet applications that Symantec Web Gateway is not aware of.

If you block Internet access for an application, the application typically does not function normally or displays an error to the user. The cause of the malfunction may not be apparent to the user. As a best practice, you should notify users of the types of applications that you block as part of your site policy.

To configure policies for Internet applications

  1. Specify the policy name and the range of computers to include in the policy.

    See Specifying computers or users for policies.

  2. Continuing on the Policies > Configuration page, locate Application Control Categories.

  3. To specify the default action type for all Internet applications that are known to Symantec Web Gateway, click one of the following options:

    Block All

    By default, block all applications from accessing the Internet. Attempts to use blocked applications are displayed in reports.

    Allow All

    By default, allow all applications to access the Internet.

    Monitor All

    By default, monitor all applications that access the Internet. Internet access for applications is allowed but application usage is displayed in reports.

    Details All

    Expand the categories to display the actions for specific applications.

    You can individually set the action options for specific categories or applications after selecting one of these options.

  4. To specify the action type for categories, click one of the following options for the category:

    Block

    By default, block applications in this category from accessing the Internet. Attempts to use blocked applications are displayed in reports.

    Allow

    By default, allow applications in this category to access the Internet.

    Monitor

    By default, monitor Internet applications in this category. Internet access for applications is allowed but application usage is displayed in reports.

    Details

    Expand the category to display the actions for specific applications. To discard individual application settings, click Block, Allow, or Monitor beside the category.

  5. Configure other policy settings as desired.

  6. Click Save.

  7. On the Policies > Configuration main page, click Save and Activate Changes.


Legacy ID



v28699519_v58977240


Article URL http://www.symantec.com/docs/HOWTO54136


Terms of use for this information are found in Legal Notices