13.07.2015 Views

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configure Hybrid FilteringTo ensure hybrid filtering users can see the notification pages when browsing withHTTPS, you need a root certificate on each client machine that can act as a CertificateAuthority for SSL requests to the hybrid proxy.NoteEnd users using <strong>Web</strong>sense Authentication Service requirethis root certificate to ensure seamless authentication toHTTPS sites. If the certificate is not installed forAuthentication Service users, they must authenticate usingNTLM identification or manual authentication, dependingon the settings on the Hybrid User Identification page. SeeDeploying <strong>Web</strong>sense Authentication Service, page 328.To install the hybrid root certificate on all clients using hybrid filtering:1. On the Hybrid Configuration > User Access page, click View Hybrid SSLCertificate.2. Save the certificate file to a location of your choice.3. Deploy the SSL certificate to your hybrid filtering users with your preferredadministration or deployment method, for example Microsoft Group PolicyObject (GPO) or a third-party deployment tool.Once you have distributed the certificate, mark Use the hybrid SSL certificate todisplay a notification page for HTTPS requests when required, then click OK tocache your changes. Changes are not implemented until you click Save and Deploy.What is a PAC file?<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> | <strong>Web</strong> <strong>Security</strong> Solutions | <strong>Version</strong> <strong>7.7</strong>.xA Proxy Auto-Configuration file is a JavaScript function definition that a browsercalls to determine how to handle requests. The PAC file used to enable hybrid filteringcontains a number of global settings and allows you to configure sites (for example,intranet sites or organizational <strong>Web</strong> mail) that users can access directly, withoutsending the request to the hybrid service (see Specify sites not filtered by hybridfiltering, page 218).If you want to use hybrid filtering on client machines, you must configure browsersettings on each of the clients to point to the URL hosting the PAC file. This URL isdisplayed on the Hybrid Configuration > User Access page in <strong>TRITON</strong> - <strong>Web</strong><strong>Security</strong> (see Configure user access to hybrid filtering, page 220).The exact mechanism for configuring a browser to use the PAC file depends on thebrowser and network environment. For example, if you are using Microsoft ActiveDirectory and Internet Explorer or Mozilla Firefox, you have the option to automatethe process via group policies. Users can also be instructed to set up their browsersmanually.<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> 225

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!