How to block a website using string value thru Intrusion prevention Sigantures?
Updated: 19 Oct 2009
Reference: How to block/allow website access using the Symantec Endpoint Protection Manager custom Intrusion Prevention Signature policy?
http://service1.symantec.com/support/ent-security.nsf/docid/2008070803545448
Idea:
I am trying to block a site which contains "porn" using wildcard.. (For example: rule tcp, dest=(80,8080), msg="Porn Blocked (Test Only)", content="www.*porn*.com". As per Symantec, the only thing I can block is the whole url of the website and using wildcard is not applicable for creating a signature. This feature can be optimized if my idea can be resolved.
idea Filed Under: