Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Configuring ACLs for Web Content Classification
The WebCC feature in Branch Gateways allows your network administrators to analyze the website usage by clients. Branch Gateways classify the usage pattern based on web categories and website reputation scores; it allows your network administrators to take appropriate measures to prevent malicious malware, spyware, or adware by blocking dangerous websites.
To configure an ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. rule for website content classification, complete the following steps:
- To configure a Branch Gateway group or a Branch Gateway, complete either one of these steps:
-
To select a gateway group:
-
In the Classic Central app, set the filter to a group that contains at least one Branch Gateway.
The dashboard context for a group is displayed.
-
Under , click > .
A list of gateways is displayed in the List view.
-
Click .
The configuration page is displayed for the selected group.
-
-
To select a gateway:
-
In the Classic Central app, set the filter to Global or a group that contains at least one Branch Gateway.
-
Under , click > .
A list of gateways is displayed in the List view.
-
Click a gateway under .
The dashboard context for the gateway is displayed.
-
Under , click .
The gateway device configuration page is displayed.
-
- If you are in the Basic Mode, click Advanced Mode to access the advanced configuration.
- Click > .
- Click the
icon in the Policies table to create a new policy. - Select a policy type from the drop-down list.
- Enter the policy name in the field.
- Click Save.
- From the list of policies, select the policy you just created.
- Click the
icon in the Policy > <policy name> Rules table. - In the<policy name> > New forwarding Rulesection, perform the following steps:
-
Select from the drop-down list and configure the following:
- Select a Web category from the drop-down list.
- From the drop-down list, select one of the following reputation scores based on your requirement:
- —These are high risk sites. There is a high probability that the user will be exposed to malicious links or payloads.
- —These are benign sites and may not expose the user to security risks. There is a low probability that the user will be exposed to malicious links or payloads.
- —These are generally benign sites, but may pose a security risk. There is some probability that the user will be exposed to malicious links or payloads.
- —These are suspicious sites. There is a higher than average probability that the user will be exposed to malicious links or payloads.
- —These are well known sites with strong security practices and may not expose the user to security risks. There is a very low probability that the user will be exposed to malicious links or payloads.
- From the drop-down list, select to not allow user to access this web category; else, select to allow user to access the web category.
- For , enter a value.
- From the drop-down list, select a suitable time range during which you want the policy to be active or valid. Alternatively, you can also create a new time range by clickingthe
icon. - From the drop-down list, select a priority from 1-7.
- For , select , and , or any other option that is applicable.
- Click .
The Add policy pop-up window is displayed.
The Policy > <policy name> Rules table is displayed.
The <policy name> > New forwarding Rule table is displayed.
The following animation shows you how to configure ACLs for Web Content Classification.
