Endpoint Protection Small Business Edition

 View Only
  • 1.  Using wildcards for blocking URL's (hosts/IPs)

    Posted Mar 13, 2011 10:22 PM

    Hi.  I want to allow all outgoing/incoming traffic to (for example) www.yahoo.com/finance but reject both traffic for www.yahoo.com/* (i.e. only allow yahoo finance but reject all other yahoo urls).

    Is this supported by Endpoint Protection?

    Also, are hosts or IP's supported for Endpoint Protection Firewall configuration, or are both supported?  Thanks.



  • 2.  RE: Using wildcards for blocking URL's (hosts/IPs)

    Posted Mar 14, 2011 11:56 AM

    How to Restrict Users to Specific Web Sites by Creating Firewall Rules for Managed Clients

    http://www.symantec.com/business/support/index?page=content&id=TECH92097&actp=search&viewlocale=en_US&searchid=1300118127914



  • 3.  RE: Using wildcards for blocking URL's (hosts/IPs)
    Best Answer

    Trusted Advisor
    Posted Mar 15, 2011 08:28 AM

    Hello,

    Follow this steps as You do not want the users to visit to any website except for certain sites no matter what browser they use.

    Solution

    The above configuration can be done by creating only 2 firewall rules. Please follow the below steps to configure the rules.

    1. Go to Firewall policy > Rules.

    2. Click on Add Rule button. Select Host > Next > From Address Type drop down menu select DNS domain.

    3. Select DNS Domain as *.* then Click Next > Click Finish.

    4. Once the rule is created, highlight the New Rule. Go to Service column, right click and edit, then select Add. The rule will be TCP, Source/destination with remote port 80,443 click ok and ok again. Then go to Action column and make it set to "Block".

    The above rule is to block all the websites. To create a rule to allow only selected websites, please follow the steps below.

    1. Go to firewall policy> Rules.

    2. Click on Add Rule. Select Host > Next > From Address Type drop down menu select DNS domain.

    3. Enter DNS Domain as *.*symantec*.* This is an example which means all the urls related to symantec will be allowed.

    4. Click Next > Click Finish. Multiple websites can be added to the same rule.

    5. Once the rule is created, highlight the new rule. Go to Action column and make it to Allow.

    Note: Place the "Allow" rule on top of "Block" rule.

    Assign the policy to the required group. This will allow only the selected website and block all other website.

    Caution: If the above rule is applied to the SEPM itself, we need to allow Symantec domain in order to run the liveupdate. This should be applicable to all the machine where Liveupdate will run.



  • 4.  RE: Using wildcards for blocking URL's (hosts/IPs)

    Posted Mar 15, 2011 12:43 PM

    As far as I know this is not possible...