Previous Topic: SSL Decode TagsNext Topic: IP Address and Port Filters


Example NBA Policy File

The NBA policy XML file defines the network filters and application filters. It also identifies the policy engines or hubs available to the NBA. Finally, it specifies the logging levels for NBA operations.

<?xml version="1.0" encoding="UTF-16"?> 
<wigan xmlns:xsi="http://www.w3.org/1999/XMLSchema-instance" xsi:noNamespaceSchemaLocation="wigan://NBAPolicy v1.0"> 
    <networkagent> 
        <description type="stringType" value="This text is logged when  
         a new policy is ingested by the NBA."/> 
        <online type="booleanType" value="true"/> 
        <active type="booleanType" value="true"/> 
        <applicationfilters enabled="true"> 
            <filtergroup enabled="true"> 
                <groupname value="File group"/> 
                <applicationfilter enabled="true"> 
                    <filtername type="stringType" 
                     value="NBA Application Filter 1"/> 
                    <ipaddrlist type="stringListType"> 
                        <element value="*"/> 
                    </ipaddrlist /> 
                    <protocols type="stringListType"> 
                        <element value="ALL"/> 
                        <element value="HTTPURL"/> 
                    </protocols> 
                    <action type="simpleStreamBlockEnumeration" value="analyze"/> 
                    <loglevel type="simpleEnumLogLevel" value="error"/> 
                </applicationfilter> 
            </filtergroup> 
        </applicationfilters>
        <networkfilters enabled="true"> 
            <filtergroup enabled="true"> 
                <groupname value="main group"/> 
                    <networkfilter enabled="false"> 
                        <filtername type="stringType" 
                         value="NBA Network Filter 1"/> 
                        <ipaddrlist type="stringListType"> 
                            <element value="*"/> 
                        </ipaddrlist > 
                        <protocols type="stringListType"> 
                            <element value="ALL"/> 
                        </protocols > 
                        <action type="simpleStreamBlockEnumeration" 
                         value="analyze"/> 
                        <loglevel type="simpleEnumLogLevel" value="error"/> 
                    </networkfilter> 
            </filtergroup> 
        </networkfilters> 
        <settings> 
            <enterprisednslist type="stringListType"> 
                <element value = "unipraxis.com"/> 
                <element value = "unipraxis.co.uk"/> 
            </enterprisednslist> 
            <analyzeservers type="stringListType"> 
                <element value = "10.0.1.96:4456"/> 
                <element value = "10.0.1.97:4456"/> 
                <element value = "10.0.1.98:4456"/> 
            </analyzeservers> 
            <standbyanalyzeservers type="stringListType"> 
                <element value = "10.0.1.96:4456"/> 
                <element value = "10.0.1.97:4456"/> 
                <element value = "10.0.1.98:4456"/> 
            </standbyanalyzeservers> 
            <ssl>
                <domainexcludelist type="stringListType">
                    <element value="update.microsoft.com"/>
                    <element value="download.microsoftupdates.com"/>
                    <element value="activation.sls.microsoft.com"/>
                    <element value="windowsupdate.microsoft.com"/>
                </domainexcludelist>
                <serverexclusioncache type="booleanType" value="false"/>
                <clientexclusioncache type="booleanType" value="false"/>
            </ssl>
            <capturepartialobjects type="booleanType" value="false"/> 
            <captureftplogs type="booleanType" value="false"/> 
            <htmlblocktemplate type="stringType"" value="blocktemplate.html"/> 
            <prohibittitle type="stringType"" value="Unipraxis Advisory"/> 
            <prohibitmessage type="stringType"" value="This Web site is blocked."/> 
            <logging> 
                <numberoflogfiles type="numberType" value="10"/> 
                <maxsizeoflogfileskb type="numberType" value="1024"/> 
                <loglevel type="simpleEnumLogLevel" value="error"/> 
                <logrolloverhours type="numberType" value="0"/> 
                <statslogintervalsecs type="numberType" value="60"/> 
            </logging> 
        </settings> 
    </networkagent> 
</wigan>