Configure Traffic Types in a Firewall Policy

Applies To: Cloud-managed Fireboxes

For firewall policies on a cloud-managed Firebox, the Web Traffic and Traffic Types settings specify the types of traffic the policy applies to. When you add traffic types to a policy, you can select from a list or add a custom traffic type. Each traffic type specifies the protocols and ports the policy applies to.

Screenshot of the Web Traffic and Traffic Types section in an outgoing policy

Configure Web Traffic Settings

In Outbound policies, two settings specify how the policy applies to web traffic:

Web Traffic

This setting configures the policy to apply to HTTP and HTTPS traffic on specified ports. By default, this check box is selected, and the policy applies to HTTP and HTTPS traffic on ports 80 and 443. To change the ports for HTTP and HTTPS traffic, you can edit the ports list.

When Web Traffic is selected, the policy applies to HTTP and HTTPS traffic but the HTTP and HTTPS protocols do not show in the Traffic Types list.

HTTP and HTTPS traffic are strictly enforced when Web Traffic is selected. To avoid denials, you must create a First Run policy to allow other traffic sent over ports 80 and 443. 

Decrypt HTTPS Traffic

This setting configures the policy to decrypt HTTPS traffic. When you select Decrypt HTTPS Traffic, the Firebox decrypts HTTPS connections and scans the content with enabled security services. If the policy allows the content, the Firebox then re-encrypts the HTTPS connections with a different certificate.

Before you enable Decrypt HTTPS Traffic, make sure that network clients trust the certificate the Firebox uses to re-encrypt the content. To avoid browser errors for network clients, download the Firebox certificate and import it to all network clients. For more information, go to Download the Certificate for TLS Decryption.

To avoid certificate warnings for network users, Decrypt HTTPS Traffic is disabled by default.

When you select Decrypt HTTPS Traffic on a web traffic policy, you can enable and configure these features: 

To configure a First Run, Last Run, Inbound, or Custom policy to apply to web traffic, add the HTTP and HTTPS traffic types to the Traffic Types list.

Select Traffic Types in a Policy

In the Traffic Types list for a firewall policy you can add predefined and custom traffic types.

In a firewall policy for a cloud-managed Firebox, you can select multiple traffic types in the same policy. This is different from firewall policies for a locally-managed Firebox.

Related Topics

Configure Firewall Policies in WatchGuard Cloud

Firewall Policy Types

SafeSearch Enforcement in WatchGuard Cloud

Google Apps Allowed Domains in WatchGuard Cloud

Fastvue in WatchGuard Cloud

URL Path Keyword Filtering in WatchGuard Cloud