Whitelist Applications

You can create a policy to block everything except a single application or small group of applications (or web sites).

To whitelist one or more applications:

  1. Select Configure > Roles from the menu.
  2. Select Add to add a new role. Alternatively, select an existing role to open the Configuration page.
  3. Create a Deny policy to block everything. This policy can be assigned to a public user SSID.
  4. Add an extended application policy to allow a single web site. From the Configure Role page, select New Application Policy.
    A new row is added to the Rules list.
  5. Select GUID-19C6669C-6510-4661-B54F-B5EA333B6046-low.png and configure the application rule.
  6. Next to the Application field, select GUID-8165B5C2-DE95-4E21-885A-564BBC1A5461-low.png.
    The Custom Applications dialog opens.
  7. Select Create New Application and configure the fields in the Application Setting dialog that opens. For example, to allow access to www.companyname.com, enter Web Applications as the group, Company Name as the name, and www.companyname.com as the pattern.
    Group Specify the application group to which the application belongs. The groups are pre-defined and cannot be customized.
    Application Name Enter a unique name for the custom application.
    Pattern Enter all or part of a fully qualified domain name (FQDN). The rule will match if the text that you enter appears anywhere in the host header of HTTP traffic. Example: The pattern companyname will match 'www.companyname.com', 'companyname.com' and 'www.company-name.com'. The match is case sensitive, so the pattern will not match 'Companyname.com'.
  8. Repeat step 4-7 as needed to add additional individual web sites that each allow one web site. For example, if you want to allow five web sites, make an extended application rule for each web site, for a total of 5 extended application rules.