Question

URL white listing

  • 6 February 2024
  • 1 reply
  • 101 views

Can we allow only specific URL and block every other web application in browser using NG SWG solution??

If yes, how do we set a policy??


1 reply

Userlevel 5
Badge +16

Netskope's SWG policy is, by nature, one based on providing access.  There is an (undisplayed) implicit permit at the end of the policy that permits all traffic not previously blocked.  In fact, if you want this traffic logged; you would need to add a similar permit rule at end of your policy.

 

 

qyost_0-1706708508767.png

I use categories rather than "Any Web Traffic" to eliminate the need for a Source criteria. This does leave you open to potentially leaking traffic out when new categories are introduced unless you remember to update the policy to include them.  The "All Categories" selection just adds the existing categories.

 

To block all traffic not previously permitted, you would need to either make another policy ahead of that rule (preserving documentation of the implied rule, even if it's never hit) 
 

qyost_1-1706709051343.png

Alternatively, you could just change the previously defined Explict rule to a block. 

 

Reply