ProxySG & Advanced Secure Gateway

 View Only
  • 1.  How to block IP adresses on ProxySG ?

    Posted Aug 20, 2018 10:06 AM

    Hi all,

     

    I'm wondering how to block all IP adresses on my ProxySG and let only URL to be used in browsers ?

     

    I think it should be a simple web access layer rule with a special destination type model.

     

    thanks in advance

     

    regards,



  • 2.  RE: How to block IP adresses on ProxySG ?

    Posted Aug 20, 2018 10:59 AM

    Hi,

     

                 This can be achieved by using the trigger of "url.host.is_numeric=yes". Details on article https://support.symantec.com/en_US/article.TECH241671.html



  • 3.  RE: How to block IP adresses on ProxySG ?

    Posted Aug 21, 2018 03:42 AM

    Thank you Aravind, I will try that , but is there a way to do on a CPL layer on VPM ? or on destination feild ?

     

    I prefer not to change local policy file



  • 4.  RE: How to block IP adresses on ProxySG ?

    Posted Aug 21, 2018 04:21 AM

    Hi,

     

                  You can use the same policy on a VPM CPL Layer too. It is not a must to have it on local policy file. There is no pre-defined destination object for this in VPM. Still one can use a destination match with url.regex as in the screenshot below (This regex method is not recommended though as it might match if an IP address is mentioned anywhere in the url and needs bit more CPU/Memory)

     



  • 5.  RE: How to block IP adresses on ProxySG ?

    Posted Aug 21, 2018 04:35 AM

    Yeahh that's a great solution thank you Aravind