This section describes the verification and check operations after the file blocking feature is configured.
After configuring the file blocking feature, you can do as follows to check the configuration result:
Check the file blocking profile.
Choose , click the name of the file blocking profile to be checked, and verify that the parameter settings in the profile are correct.
Check the security policy configuration.
Choose , click the name of the security policy to be checked, and verify that the file blocking part correctly references the file blocking profile.
After referencing the file blocking profile in the security policy, the FW checks the files matching the security policy. If a transferred file matches a file blocking rule, a content log is generated.
Choose to view content logs. The following table lists the fields in a content log.
Field |
Description |
|---|---|
View |
Click In View Content Log Details, click the Source Region/Destination Region/Source Address/Destination Address/Source User/Application/Security Policy/Profile field value. You can view and operate existing field settings. |
Time |
Time when a content log is generated |
Type |
Content log types:
|
File Name |
Name of a file |
File Type |
Type of a file |
Source Zone |
Source security zone of traffic |
Destination Zone |
Destination security zone of traffic |
Source Region |
Source region of the traffic |
Destination Region |
Destination region of the traffic |
Source Address |
Source IP address of traffic |
Destination Address |
Destination IP address of traffic |
Source User |
User who generates traffic |
Source Port |
Source port of traffic |
Destination Port |
Destination port of traffic |
Application |
Application type of traffic |
Action |
Action defined in the data filtering rule, file blocking rule, or application behavior control rule that traffic matches |
Security Policy |
Security policy that traffic matches |
Profile |
Security profile that traffic matches |
Virtual System |
Virtual system that generates the traffic |