13.07.2015 Views

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User IdentificationIdentification of hybrid filtering users<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> | <strong>Web</strong> <strong>Security</strong> Solutions | <strong>Version</strong> <strong>7.7</strong>.xRelated topics: <strong>Web</strong>sense Directory Agent, page 330 When users are not identified, page 332 Authentication priority and overrides, page 324 Working with hybrid filtering clients, page 88Select Settings > Hybrid Configuration > Hybrid User Identification to configurehow users are identified by the hybrid service, and to test and configure users’connections to the service. You can configure multiple authentication or identificationoptions for your hybrid users if required.To ensure that the appropriate per-user or per-group policy is applied to hybridfiltering users, whether from a filtered location or when off-site, <strong>Web</strong>sense <strong>Web</strong><strong>Security</strong> Gateway Anywhere provides options for identifying hybrid filtering userstransparently:<strong>Web</strong>sense <strong>Web</strong> Endpoint is installed on client machines to provide transparentauthentication, enforce use of hybrid filtering, and pass authentication details tothe hybrid service. See <strong>Web</strong> Endpoint deployment overview, page 325.<strong>Web</strong>sense Authentication Service provides clientless transparent authenticationvia a gateway hosted on your network. See Deploying <strong>Web</strong>sense AuthenticationService, page 328.If you do not deploy either <strong>Web</strong> Endpoint or Authentication Service, the hybridservice can identify users transparently or manually when they connect to hybridfiltering.Users can only be identified transparently via NTLM if they are logging on from aknown IP address, defined as a filtered location (see Define filtered locations,page 211). Note that NTLM identification is not available for off site users.The hybrid service can be configured to automatically generate passwords for allusers whose information is collected by Directory Agent (see Configure useraccess to hybrid filtering, page 220).If you do not enable any form of transparent authentication:• Off site users without <strong>Web</strong> Endpoint or Authentication Service are promptedfor an email address and password when they open a browser and connect tothe Internet.• Other hybrid filtering users are filtered based on their IP address if <strong>Web</strong>Endpoint, Authentication Service, or NTLM identification are not available.Indicate how the hybrid service should identify users requesting Internet access. Theseoptions are also used as a fallback if either the endpoint or Authentication Servicefails.322 <strong>Web</strong>sense <strong>Web</strong> <strong>Security</strong> Solutions

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!