Procedure:
Edit Reputation settings
Reputation settings apply to all Reputation filters in a profile.
- Select Profiles > Inspection Profiles > [Profile Name] > Reputation/Geo.
- Click Edit Settings.
- Select Locked to lock the settings for all Reputation filters in the profile.
- Select a Filter Matching Address to specify which address of an incoming packet is used when it matches a Reputation filter.
- Select a Lookup Packet Handling option to specify what the device should do with incoming packets during a Reputation lookup.
- Click OK
Create or edit a Reputation filter
- Select Profiles > Inspection Profiles > [Profile Name] > Reputation/Geo.
- Do one of the following:
- Click New Reputation to create a new Reputation filter.
- Select an existing Reputation filter, and click Edit.
- Enter a filter title in the Name field, and then select the Locked check box to prevent the ability to edit the filter.
- Select the appropriate block or permit action from the Action Set drop-down list, and select the Enabled check box to enable the filter. If you clear this check box, the Reputation filter will not be distributed to the device.
- Provide a brief description or comment about the Reputation filter in the Comments field (Optional).
- Click Entry Selection Criteria and specify the following items:
- Entry Criteria - determines the type of address entries from the Reputation Database to include in the filter.
-
NOTE: If the tag criteria contains Does not have this tag, the SMS sends all entries that do not have this tag category to the device including Reputation DV, geographic, and user-provided entries when you distribute the profile.
- Click OK.
Change the precedence of a Reputation or Geographic filter (move up/down)
- Select Profiles > Inspection Profiles > [Profile Name] > Reputation/Geo.
- Select a Reputation or Geographic filter from the table, and then click the appropriate button:
- Click Move Up to move the highlighted entry up.
- Click Move Down to move the highlighted entry down.
- The new order is automatically saved.
Delete a Reputation or Geographic filter.
- Select Profiles > Inspection Profiles > [Profile Name] > Reputation/Geo.
- Select a Reputation or Geographic filter from the table, and then click Delete. A dialog appears in which you can confirm the deletion.
Create or edit Reputation filter exceptions.
- Go to Profiles > Inspection Profiles > Default > Reputation/Geo
- Click the Exceptions tab.
- To edit an existing Reputation filter exception (IP, DNS, or URL), select an exception name, and then click Edit.
- To create a new Reputation filter exception, click Add.
- (Optional) Select Locked if you want to lock the settings.
- Type a name for the exception in the Name field.
- In the Source IP Address field, do one of the following:
- Select Any IP to apply the restriction to all traffic sources.
- Select IP Address, and provide or select an IP address to apply the restriction to that specific source.
- In the Destination IP Address field, enter an IP address and do one of the following:
- Select Any IP to apply the restriction to all traffic destinations.
- Select IP Address, and specify an IP address to apply the restriction to that specific destination.
- Click OK.
Create or edit domain name exceptions
- Go to Profiles > Inspection Profiles > Default > Reputation/Geo
- Click the DNS Exceptions tab.
- To edit an existing domain name exception, select a domain name, and then click Edit.
- To create a new domain name exception, click Add.
- (Optional) Select Locked if you want to lock the settings.
- Type a name for the Reputation domain name in the Name field.
-
IMPORTANT: You must explicitly list each domain name that you want to exclude from the filters. Wildcards, such as an asterisk (*), do not work.
-
- Click OK.
