13.07.2015 Views

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Scanning and SSL Decryption Bypass OptionsTunneled protocol detection<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> | <strong>Web</strong> <strong>Security</strong> Solutions | <strong>Version</strong> <strong>7.7</strong>.xRelated topics: Scanning options, page 189 Content categorization, page 190 <strong>Security</strong> threats: Content security, page 193 <strong>Security</strong> threats: File analysis, page 194 Outbound security, page 196 Advanced options, page 197 Scanning exceptions, page 199 Reporting on scanning activity, page 202Tunneled protocol detection analyzes traffic to discover protocols that are tunneledover HTTP and HTTPS. Traffic that is allowed to tunnel over specific ports is alsoanalyzed. Such traffic is reported to <strong>Web</strong>sense <strong>Web</strong> filtering for protocol policyenforcement. When tunneled protocol detection is enabled, analysis is performed onboth inbound and outbound traffic, regardless of other scanning settings.HTTP tunneling occurs when applications that use custom protocols forcommunication are wrapped in HTTP (meaning that standard HTTP request/responseformatting is present) in order to use the ports designated for HTTP/HTTPS traffic.These ports are open to allow traffic to and from the <strong>Web</strong>. HTTP tunneling allowsthese applications to bypass firewalls and proxies, leaving a system vulnerable.The tunneled protocol detection feature analyzes HTTP and HTTPS traffic and, whenit detects a protocol, forwards it to <strong>Web</strong>sense <strong>Web</strong> filtering for policy enforcement. Atthis point, a protocol is blocked or allowed based on policy definitions. This featurecan be used to block protocols used for instant messaging, peer-to-peer applications,and proxy avoidance. Note that some applications running over HTTP (for example,Google Video) may not display the protocol block page. See Filtering categories andprotocols, page 50, for information about protocol filtering.NoteTunneled protocol detection is performed before contentcategorization. As a result, when a tunneled protocol isidentified, protocol policy is enforced and contentcategorization is not performed.Use the Settings > Scanning > Scanning Options page to enable and configuretunneled protocol detection:1. Select Off to disable tunneled protocol detection.192 <strong>Web</strong>sense <strong>Web</strong> <strong>Security</strong> Gateway

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!