01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6<br />

<strong>Web</strong> filtering<br />

SSL scanning<br />

SSL scanning<br />

5 In the Wildcard expression field, type a wildcard expression.<br />

Note: To add multiple wildcard expressions at once, click Add multiple and type every wildcard<br />

expression in a new line.<br />

6 [Optional] In the Comment field, type a comment on the wildcard expression.<br />

7 Click OK. The window closes and the wildcard expression appears on the whitelist.<br />

8 Click Save Changes.<br />

For more information on how to maintain a list, see List maintenance. For the types of wildcard<br />

expressions that are allowed in the list, see Wildcard expressions.<br />

SSL-secured requests can be inspected by an SSL scanning module before other appliance functions<br />

filter them. This section explains the SSL scanning process and tells you how you can modify it.<br />

The rules in a rule set for SSL scanning call the SSL scanning module to let it verify the certificates sent<br />

with SSL-secured requests. If certificate verification does not lead to blocking a request, the rules call<br />

the module to enable content inspection and have the request filtered by the other implemented rule<br />

sets.<br />

The rules also handle the CONNECT request that SSL-secured communication begins with if it does not<br />

use the transparent mode. Whitelists of hosts and certificates can be used to skip certificate verification<br />

and content inspection.<br />

Rules for SSL scanning<br />

To use SSL scanning on the appliance, a rule set containing appropriate rules must be implemented.<br />

This section describes a sample rule set from the library.<br />

A rule set for SSL scanning contains rules for handling the different types of requests that a client sends<br />

to the appliance in SSL-secured communication and for enabling certificate verification and content<br />

inspection. Other rules whitelist requests if, for example, the host or the certificate that a request is<br />

related to are on a whitelist.<br />

SSL Scanner<br />

This section describes the rules in a library rule set for SSL scanning.<br />

For general information on understanding and handling rules, see Rules and rule sets.<br />

Library rule set — SSL Scanner<br />

Criteria — Always<br />

Cycle — Requests (and IM)<br />

The following rule sets are nested in this rule set:<br />

• Handle Connect Call<br />

• Certificate Verification.<br />

• Verify Common Name (proxy setup)<br />

• Content Inspection<br />

• Verify Common Name (transparent setup)<br />

216 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!