This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

how to block certain types of file

hello 

how can i let my sophos xg disable download or opening of certain types of file like htm or jar for everyone ?!

please advise



This thread was automatically locked due to age.
Parents
  • This can be configured under Web Policies.

     

    You can create a custom Web Policy and add all the file types you want to block in or use a pre existing one.

    Just be careful though as if you have Exceptions added with Skip Policy checks these files will still come through from those URLs  and sites in the exceptions

     

    You can also set who it applies to if you have user groups set up.

  • i want to set it up for the entire network

    if i create it and use it as first rule in the firewall .. how will the following rules react ?

    per example i have rule # 2 to give internet to X.X.X.X ip and rule # 3 to deny internet to y.y.y.yip .. if i set a rule # 1 with only blocking certain file type for everyone , would rule #2 and rule # 3 works normally while still blocking the files i do not want ?

     

    in other terms i want to block the files for everyone without affecting my current config 

  • The firewall uses the top down approach

    So if your first rule was just a web filter affecting those file types then the users would hit that rule for just that and then go to rule 2 etc for normal network.

    Just enable the new Web Policy as rule 1 and then check the log viewer for any issues - normally users scream pretty quick when they cant get to the internet :-)

    The very last rule is usually a default rule that blocks everything

Reply
  • The firewall uses the top down approach

    So if your first rule was just a web filter affecting those file types then the users would hit that rule for just that and then go to rule 2 etc for normal network.

    Just enable the new Web Policy as rule 1 and then check the log viewer for any issues - normally users scream pretty quick when they cant get to the internet :-)

    The very last rule is usually a default rule that blocks everything

Children