SonicOS 7.1 Rules and Policies for Classic Mode

About Content Filter Rules

A Content Filter policy determines whether a packet is filtered (by applying the configured CFS Action) or simply allowed through to the user. In SonicOS, Content Filter policies can contain inclusion and exclusion objects for Source Address and User/Group. A Content Filter policy defines the filtering conditions to which a packet is compared:

  • Name
  • Source Zone
  • Destination Zone
  • Source Address Included
  • User/Group Included
  • Schedule
  • Source Address Excluded
  • User/Group Excluded

If a packet matches all the defined conditions, the packet is filtered according to the corresponding CFS Profile, and the CFS Action is applied.

If authentication data for User/Group is not available during matching, no match is made for this condition. This strategy prevents performance issues, especially when Single Sign-On is in use.

Each Content Filter policy has a priority level, and policies with higher priorities are checked first.

CFS uses a policy table internally to manage all the configured policies. For each policy element, the table is constructed by the configuration data and runtime data. The configuration data includes parameters that define the policy from the user interface, such as policy name, properties and others. The runtime data includes the parameters used for packet handling.

CFS also uses a policy lookup table to accelerate runtime policy lookup for matching conditions:

  • Source zone
  • Destination zone
  • IPv4 Address Object
  • IPv6 Address Object

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden