Application Policies
For instructions on configuring application control policies, refer to Creating an Application Control Policy.
Configuring application control policies allows the administrator to deny application access by blocking any HTTP host name (Fully Qualified Domain Name [FQDN]) or Layer 4 port. Using application denial policies, administrators can block specific applications if they are seen to be consuming excessive network resources, or enforce network usage policies such as blocking social media sites.
When defining application control policies, you must consider the following FQDN constructions depending on the desired rule actions:
- "www.corporate.com": Blocks access to the host web server at the organization "corporate.com", that is, the FQDN. It will not block access to any other hosts such as FTP, NTP, SMTP, and so on at the organization "corporate.com".
- "corporate.com": Blocks access to all hosts at the domain "corporate.com", that is, it will block access to www.corporate.com, ftp.corporate.com, smtp.corporate.com, and so on.
- "corporate": Blocks access to any FQDN containing the text "corporate" in any part of the FQDN. Care should be taken to use a string that is as long as possible for matching to prevent inadvertently blocking sites that may contain a shorter string match; for example, if the rule is "net", then this will block access to any sites that have the text "net" in any part of the FQDN or ".net" as the FQDN suffix.
- "*.corporate.com": An invalid rule. The "*" wildcard and other regular expressions cannot be used in any part of the FQDN.
- "www.corporate.com/games": An invalid rule. The filter cannot parse and block access on text after the FQDN; in this example, it cannot filter the microsite "/games".