13.07.2015 Views

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configure Hybrid FilteringConfigure how data is gathered for hybrid filtering<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> | <strong>Web</strong> <strong>Security</strong> Solutions | <strong>Version</strong> <strong>7.7</strong>.xUse the Shared User Data > Active Directory (Native Mode) page to refine the waythat Directory Agent searches the selected directory server and packages user andgroup information for the hybrid service.Under Root Context for Hybrid Filtering Users, click Add to provide a Root Contextto use when gathering user and group data from the directory. Narrow the context toincrease speed and efficiency. See Adding and editing directory contexts, page 231.WarningThere is a limit to how many groups the hybrid service cansupport. The limit is affected by a number of factors, but ifit is exceeded, user requests are not filtered properly (theservice fails open).If your organization has a large directory forest withthousands of groups, be sure to configure Directory Agentto upload only the information required to filter the userswhose requests are sent to the hybrid service. You mightselect only specific groups to upload, or set a specific andnarrowed root context.It is best to provide contexts that include only users filtered by the hybrid service.If you are using Active Directory and have multiple Directory Agent instances, makesure that each has a unique, non-overlapping root context. Especially watch out forthis if:Multiple Directory Agent instances are configured to connect to domaincontrollers that all manage the same Active Directory server.One Directory Agent instance is configured to communicate with an ActiveDirectory parent domain and another instance is configured to communicate withan Active Directory child domain (a separate global catalog server).You can further refine the data that is sent to the hybrid service by defining patterns, orsearch filters, used to remove duplicate or otherwise unwanted entries from thedirectory search results. See Optimizing search results, page 233, for moreinformation.Oracle (Sun Java) Directory Server and hybrid filtering<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> | <strong>Web</strong> <strong>Security</strong> Solutions | <strong>Version</strong> <strong>7.7</strong>.x<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> 229

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!