01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Web</strong> filtering<br />

SSL scanning 6<br />

Handle CONNECT Call<br />

This nested rule set handles the CONNECT call in SSL-secured communication and enables certificate<br />

verification.<br />

Nested library rule set — Handle Connect Call<br />

Criteria — Command.Name equals “CONNECT”<br />

Cycle — Requests (and IM)<br />

The rule criteria specifies that the rule set applies if a request is received on the appliance that contains<br />

the CONNECT command, which is sent in the opening phase of SSL-secured connection.<br />

The rule set contains the following rules:<br />

Set client context<br />

Always –> Continue — Enable SSL Client Context with CA <br />

The rule enables the use of a server certificate that is sent to a client. The event settings specify the<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> root certificate authority (CA), which is implemented on the appliance after<br />

the initial setup, as the default issuer of this certificate.<br />

Tunneled hosts<br />

URL.Host is in list SSL Host Tunnel List –> Stop Cycle<br />

The rule lets requests for access to hosts with a URL that is on the specified whitelist skip SSL<br />

scanning.<br />

Restrict destination ports to Allowed CONNECT Ports<br />

URL.Port is not in list Allowed Connect Ports –> Block<br />

The rule blocks requests with destination ports that are not on the list of allowed CONNECT ports.<br />

The action settings specify a message to the requesting user.<br />

Enable certificate verification without EDH for hosts in no-EDH server list<br />

URL.Host is in list No-EDH server –> Stop Rule Set — Enable SSL Scanner<br />

The rule enables the certificate verification for requests sent from a host on the no-EDH<br />

(Ephemeral Diffie-Hellman) server list.<br />

The event settings specify running in verification mode for the SSL scanning module and a special<br />

cipher string for data encryption on non-EDH hosts.<br />

Enable certificate verification<br />

Always –> Stop Rule Set — Enable SSL Scanner<br />

The rule enables certificate verification. The event settings specify that the SSL scanning module<br />

runs in verification mode.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 217

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!