01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Authentication and access management<br />

Quota management 5<br />

User Database at Authentication Server<br />

Settings for the Authentication module specifying the User Database method for cookie authentication.<br />

Meaning and usage of these settings are the same as for the settings of the module when it uses the<br />

Authentication Server method for standard authentication.<br />

For more information, see User Database.<br />

Quota management<br />

You can guide the users of your network by imposing time and volume quotas and other restrictions on<br />

their web usage. This section explains these restrictions and tells you how to configure them.<br />

Restricting web usage through quota management<br />

Quotas for restricting the web usage of users can be imposed in several ways. Like other functions on<br />

the appliance, quotas are implemented by rules that use lists and call modules to retrieve relevant<br />

information. This section provides an overview of quota restrictions and the appliance functions that are<br />

related to them.<br />

Time quota<br />

By configuring time quotas, you can limit the time that users of your network are allowed to spend for<br />

web usage. Time quotas can be related to several parameters:<br />

• URL categories — When time quotas are related to URL categories, users are allowed only a limited<br />

time for accessing URLs that fall into particular categories, for example, Online Shopping.<br />

• IP addresses — When time quotas are related to IP addresses, users who send requests from<br />

particular IP addresses are allowed only a limited time for web usage.<br />

• User names — When time quotas are related to user names, users are allowed only a limited time<br />

for web usage. Users are identified by the user names they submitted for authentication on the<br />

appliance.<br />

Note: These parameters are used by the rules in the library rule set for time quotas. You can create rules of<br />

your own that use other parameters in relation to time quotas.<br />

The time that users spend on web usage is stored on the appliance. When the configured time quota<br />

has been exceeded for a user, a request that this user sends is blocked. A message is displayed to the<br />

user stating why the request was blocked.<br />

Users are identified by the user names they submitted for authentication. If no user name is sent with<br />

a request, web usage is recorded and blocked or allowed for the IP address of the client system that the<br />

request was sent from.<br />

<strong>Web</strong> usage can be limited to time spent per day, per week, or per month.<br />

Volume quota<br />

By configuring volume quotas, you can limit the volume of web objects, measured in GB and MB, that<br />

the users of your network are allowed to download from the web. Volume quotas can be related to<br />

several parameters:<br />

• URL categories — Users are allowed to download only a limited volume of web objects through URLs<br />

that fall into particular categories, for example, Streaming Media.<br />

• IP addresses — Users who send download requests from particular IP addresses are allowed only a<br />

limited volume.<br />

• User names — Users are allowed to download web objects only up to a limited volume. Users are<br />

identified by the user names they submitted for authentication on the appliance.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 147

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!