01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

6<br />

<strong>Web</strong> filtering<br />

SSL scanning<br />

Content Inspection<br />

This nested rule set completes the handling of a CERTVERIFY call. It lets some requests skip content<br />

inspection according to particular criteria and enables inspection for all others.<br />

Nested library rule set — Content Inspection<br />

Criteria — Command.Name equals “CERTVERIFY”<br />

Cycle — Requests (and IM)<br />

The rule criteria specifies that the rule set applies if a request is received on the appliance that contains<br />

the CERTVERIFY command, which is sent to request the verification of a certificate.<br />

The rule set contains the following rules:<br />

Skip content inspection for hosts found in SSL Inspection Whitelist<br />

Connection.SSL.Transparent equals false AND<br />

URL.Host matches in list SSL Inspection Whitelist –> Stop Rule Set<br />

The rule lets requests sent to whitelisted hosts skip content inspection. It applies only in<br />

non-transparent mode.<br />

Skip content inspection for CN found in SSL Inspection Whitelist<br />

Connection.SSL.Transparent equals true AND<br />

Certificate.SSL.CN matches in list SSL Inspection Whitelist –> Stop Rule Set<br />

The rule lets requests with whitelisted common names in their certificates skip content inspection.<br />

It applies only in transparent mode.<br />

Note: This rule is not enabled by default.<br />

Do not inspect connections with client certificates<br />

Connection.Client.CertificateIsRequested equals true –> Stop Rule Set<br />

The rule lets requests skip inspection if they require the use of client certificates.<br />

Note: This rule is not enabled by default.<br />

Enable content inspection<br />

Always –> Continue — Enable SSL Scanner<br />

The rule enables content inspection. The event settings specify that the SSL scanning module runs<br />

in inspection mode.<br />

If any of the rules for skipping content inspection applies, processing of the rule set stops and this<br />

last rule, which enables the inspection, is not processed. Otherwise, content inspection is enabled<br />

by this rule.<br />

220 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!