01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Web</strong> filtering<br />

SSL scanning 6<br />

Verify Common Name (transparent setup)<br />

This nested rule set verifies the common name in a certificate. It applies only to requests sent in<br />

transparent mode.<br />

Nested library rule set — Verify Common Name (transparent setup)<br />

Criteria — Connection.SSL.TransparentCNHandling equals true AND Command.Name does not equal “CONNECT”<br />

AND Command.Name does not equal “CERTVERIFY”<br />

Cycle — Requests (and IM)<br />

The rule criteria specifies that the rule set applies if a request is received through a connection used in<br />

SSL-secured communication and verification of the common name is performed in transparent mode.<br />

The rules of the rule set check the same criteria to verify a common name as those of the Verify<br />

Common Name rule set for the non-transparent mode.<br />

However, in the latter mode, the host name to be checked is taken from the CONNECT request, which<br />

is not sent under the transparent mode. In this mode, the host name is taken from the request that is<br />

sent.<br />

For more information, see Verify Common Name (proxy setup).<br />

Lists for SSL scanning<br />

This section describes some sample lists for SSL scanning. The lists are used by the rules of the library<br />

SSL Scanner rule set.<br />

Note: When you import this rule set, the lists are also imported. You can find them on the Lists tab of the<br />

Policy top-level menu, which displays lists sorted by their types and names.<br />

For general information on how to maintain lists, see List maintenance.<br />

Allowed CONNECT Ports<br />

List of ports that are allowed CONNECT ports on destination servers<br />

Type — Number<br />

Initial entry — 443 – Default HTTPS port<br />

The following table describes the list entries.<br />

Table 6-17 Allowed CONNECT Ports list<br />

Option Definition<br />

Number Number of a port that is an allowed CONNECT port on a destination server<br />

Comment Plain-text comment on the port<br />

Certificate White List<br />

List of certificates that are not verified by the SSL scanning module<br />

Type — Host and Certificate<br />

The list is initially empty.<br />

The following table describes the list entries.<br />

Table 6-18 Certificate White List<br />

Option Definition<br />

Certificate Name of a whitelisted certificate<br />

Host Host that the certificate proves to be trustworthy (in regular expression format)<br />

Comment Plain-text comment on the certificate<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 221

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!