01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Authentication and access management<br />

Filtering users 5<br />

Sample authentication rule<br />

In the following, an example of an authentication rule is explained. This rule can be included in a rule<br />

set of the appliance library. It is shown in a notation that comes close to how the rule appears on the<br />

user interface.<br />

Name<br />

Authenticate with User Database<br />

Criteria Action<br />

Authentication.Authenticate equals false –> Authenticate<br />

In plain text, this rule could be rephrased as follows:<br />

If the user has not yet been authenticated (through information from the user database), ask this<br />

user to submit credentials for authentication.<br />

Criteria and action<br />

The structure of the rule is the same as for all other rules on the appliance. It has two main elements,<br />

the criteria and the action.<br />

If the criteria is matched, the action is taken. The user is not authenticated – if this is matched, the<br />

Authenticate action is taken.<br />

The criteria has three elements:<br />

Property Operator Value of the property<br />

Authentication.Authenticate equals false<br />

The meaning of the Authentication.Authenticate property could be rendered as “having been<br />

authenticated”. The criteria could then be rephrased as follows:<br />

Having been authenticated is false (for the user who sent the request).<br />

Property<br />

A property is something related to a web object or a user. In this rule, “having been authenticated” is a<br />

property of the user who sent a request.<br />

Property names usually have two or more parts. For the Authentication.Authenticate property, the<br />

Authentication indicates that the property has something to do with authentication in general. The<br />

Authenticate part denotes a particular aspect of authentication like “having been authenticated”.<br />

Settings<br />

The sample rule also contains two terms in angle brackets: and .<br />

Terms in angle brackets are alway settings in rules on the appliance. The settings<br />

appear next to the property Authentication.Authenticate. They are the settings of the module that this<br />

property relies on for being assigned a value.<br />

The authentication module retrieves information from a database to let the rule know that<br />

Authentication.Authenticate (“being authenticated”) has the value false for a given user.<br />

The module settings are in this rule, which means the module is to retrieve user<br />

information from the local user database.<br />

The rule action, which is Authenticate, has as its settings. Settings of an action are mainly<br />

for specifying a particular message that is sent to users who are affected by the action.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 121

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!