01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Authentication and access management<br />

Standard authentication 5<br />

The rule set has also two rules of its own, which are processed before the nested rule sets:<br />

Need to authorize Client IP?<br />

Client.IP is in range list Unauthorized IPs –> Stop Rule Set<br />

The rule uses the Client.IP property to check whether a request was sent from a client with an IP<br />

address that is in the range list for unauthorized IP addresses. If this is the case, processing the<br />

rule set stops. No activities are then carried out to authenticate a user. Processing continues with<br />

the next rule set.<br />

Note: This rule is not enabled by default.<br />

Need to authorize URL?<br />

URL is in list Unauthorized URLs –> Stop Rule Set<br />

The rule uses the URL property to check whether a URL that access was requested is in the list of<br />

unauthorized URLs. If this is the case, processing the rule set stops. No activities are then carried<br />

out to authenticate a user. Processing continues with the next rule set.<br />

Authenticate with User Database<br />

This nested rule set asks unauthenticated users to authenticate. Its authentication method is retrieving<br />

information from the internal user database.<br />

Nested library rule set — Authenticate with User Database<br />

Criteria — Authentication.IsAuthenticated equals false OR<br />

Authentication.Failed equals false<br />

Cycle — Requests (and IM)<br />

The rule set criteria specifies that the rule set applies when a user has not yet been authenticated or<br />

has undergone the authentication process, but authentication failed.<br />

The rule set contains the following rule:<br />

Authenticate with User Database<br />

Authentication.Authenticate equals false –> Authenticate<br />

The rule uses the Authentication.Authenticate property to check whether a user who sends a<br />

request for web access is authenticated. The settings that go with the property are the settings of<br />

the Authentication module. They specify that retrieving information from the internal user<br />

database on the appliance is used as the authentication method.<br />

If a user has not been authenticated by information from the internal database, the rule applies<br />

and the Authenticate action is executed. Processing stops and a message is displayed, asking the<br />

user to authenticate. The settings of the action specify that the message is displayed with default<br />

values.<br />

Processing continues when the next request is received on the appliance, which can be an<br />

authentication request by the same user.<br />

For information on how to modify the settings for the Authentication module to let the rule use a<br />

different authenticaiion method, such as NTM, LDAP, or others, see Implement an authentication<br />

method.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 125

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!