This article describes how to configure firewall rule to block traffic for shopping category

 

Prerequisites

  1. Versa headend is  installed and functional.
  2. Make sure NGFW (Next Generation Firewall ) services have enabled on the Versa FlexVNF CPE
  3. To add NGFW service on Versa FlexVNF click here

 

Configuration

  1. Login into the Versa Director and navigate to the Configuration >Templates
  2. Edit the Template associated with the Versa FlexVNF by clicking it

 

  1. On the Versa FlexVNF CPE template navigate to Configuration > Services > Next Gen Firewall > Security > Profiles > click on URL Filtering

 

 

  1. Click + to create new URL filtering profile
  2. Edit URL Filter will pop-up. Fill in the details:
  • Provide a Name to the Profile
  • Click on Category Based Action
  • Click to create Category Based Action

 

 

  1. Add Category Based Action will pop up fill in the details
  • Provide name of the action
  • Select Action as block
  • In the section Predefined Categories click on + and select the shopping category in the Predefined Category list as shown in below image

 

 

  1. Click ok

 

 

  1. And Click ok

 

 

  1. Navigate to Security > Policies and click on + to add new Policy (if default-policy is not present)
  2. Click on Rules

 

 

  1. Click on to add a rule
  2. Pop-up window is opened to Add Rule

 

 

 

  1. In the Add Rule window in the General tab provide the name for the rule (i.e Block_Shopping_Sites)

 

 

  1. Then click on Enforce tab. Rest of the tabs (Source/Destination, Headers/Schedule, Applications/URL, users/Groups are not required to be edited in this use case)
  2. In the Actions section select Apply Security Profile
  3. Select URL Filtering option and select from Drop-Down the URL Filtering Profile that we created earlier in this article.

 

 

  1. Click OK to complete the configuration.
  2. Since we have done the configuration in Template mode, commit the template to the branch/branches where you want to apply this rule.

 

Validation

The user will not be allowed to access the Facebook URL and Error is displayed on browser