01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Proxies and caching<br />

Reverse HTTPS proxy configuration 3<br />

Configure SSL certificate handling in a reverse HTTPS proxy configuration<br />

When the appliance sends SSL certificates to its clients in a reverse HTTPS proxy configuration, they<br />

must be the original certificates of the web servers that the clients request access to. You need to<br />

import these certificates to the appliance to make them available there.<br />

1 Go to Policies | Settings.<br />

2 On the Engines branch of the settings tree, select Enable SSL Client Context without CA.<br />

3 Click Add above the settings tree. The Add Settings window opens.<br />

4 In the Name field, enter a name for the settings you want to add, for example, Imported web server<br />

certificates.<br />

5 In the Define SSL Client Context (Without Certificate Authority) section, click Add under<br />

Select server certificate by host or IP. The Add Host to Certificate Mapping window opens.<br />

6 Under Define Mapping, configure settings that map the host name of a web server to its certificate.<br />

Then click OK. The window closes and the new mapping settings are added to the list.<br />

Note: Repeat this step to add mapping settings for multiple host names and certificates.<br />

7 [Optional] Do one of the following to configure the connection from the appliance to the web server:<br />

• If you do not want the server connection to be SSL-secured, select SSL-Scanner functionality<br />

applies only to client connection.<br />

Note: In this case, you also need to set up a rule that changes the network protocol from HTTPS to<br />

HTTP.<br />

• If you want the server connection to be SSL-secured, deselect SSL-Scanner functionality<br />

applies only to client connection.<br />

8 Click Save Changes.<br />

Create a rule set for setting the URL.Host property<br />

To create a rule set with rules that set the URL.Host property to the appropriate value for the IP<br />

addresses the appliance listens to, proceed as follows:<br />

1 Go to Policy | Rule Sets.<br />

2 On the rule sets tree, go to the position where you want to insert the rule set.<br />

3 Above the tree, click Add and select Rule Set. The Add New Rule Set window opens.<br />

4 Under Name, enter a suitable name for the new rule set, for example, Set URL.Host property<br />

according to particular IP addresses.<br />

5 Make sure Enable is selected.<br />

6 Under Applies to select Requests and IM.<br />

7 Under Apply this rule set, select Always.<br />

8 [Optional] Under Comment, type a plain-text comment on the rule set.<br />

Click OK. The window closes and the new rule set is inserted in the rule sets tree.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 63

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!