The Network Security appliance supports three whitelists—Generic Routing Encapsulation (GRE) traffic, port, and network. The lists allow you to control which set of ports, IP addresses, or subnets can be bypassed based on the matched known entries. No further analysis is performed. The lists also allows you to manage traffic for duplicate packets entering the Network Security appliance.
GRE traffic whitelist
GRE is a tunneling protocol that can be used to encapsulate network layer packets to transport other protocols over an IP network. GRE establishes a private point-to-to connection. Packets are analyzed and compared against a known GRE whitelist to determine whether they are GRE packets. A GRE traffic whitelist allows the appliance to whitelist all GRE packets.
Port whitelist
A port whitelist allows you to control which ports can be bypassed based on the matched known port entries for HTTP traffic. When you add the ports to a port whitelist, traffic on these ports will not be submitted for further analysis. The Network Security appliance can bypass specific types of traffic based on specific ports. A port whitelist allows the Network Security appliance to whitelist all the ports that you defined. The Network Security appliance will not submit the port entries that you defined for analysis.
Network whitelist
A network whitelist allows you to control which IP addresses or subnets can be bypassed based on the matched known network entries for which traffic is never monitored. Depending on the inline operational mode you want to use, the Network Security appliance allows incoming traffic to pass through unblocked. The Network Security appliance will not submit the IP addresses or subnets that you defined for analysis. The appliance detects traffic but will not generate alerts from the IP addresses or subnets that you defined.
Note
IPv6 addresses are also supported.
The following blocking and monitoring operations can be customized with whitelists:
Inline blocking mode—Communication to or from the addresses in the whitelist is never blocked or monitored.
Inline operation mode—Communication to or from the addresses in the whitelist is monitored but never blocked.
Submission whitelist
A submission whitelist allows you to configure rules based on IP subnets or domain names to bypass submissions for static and dynamic analysis.
Task List for managing whitelists
Complete the tasks for managing whitelists in the following order:
Log in to the Web UI or CLI.
Configure your system based on the inline operational mode you want to use. For details about how to configure operational modes for an inline policy on an interface, see Configuring inline operational modes using the Web UI or Configuring inline operational modes using the CLI .
If GRE packets must be whitelisted, enable a GRE traffic whitelist. For details about how to enable a GRE traffic whitelist, see Enabling or disabling a GRE traffic whitelist using the Web UI or Enabling or disabling a GRE traffic whitelist using the CLI.
If ports must be whitelisted, enable the ports that you want to add to a port whitelist. For details about how to enable a port whitelist, see Enabling or disabling a port Whitelist Using the Web UI or Enabling or disabling ports for a whitelist using the CLI. For details about how to add ports, see Adding ports to a whitelist using the Web UI on page 1 or Adding ports to a whitelist using the CLI.
Determine the IP addresses and subnets that you want to add to a network whitelist. For details about how to add IP addresses and subnets, see Adding rules to a network whitelist using the Web UI or Adding rules to a network whitelist using the CLI.
View the traffic statistics of packet entries on a GRE whitelist, a port whitelist, and a network whitelist. For details about how to view the statistics on each whitelist, see Viewing the traffic statistics on each whitelist using the CLI.
Determine the IP addresses, subnets and domain names that you want to add to a submission whitelist. For details about how to add IP addresses and subnets, see Adding domains to a submission whitelist using the Web UI.