01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Proxies and caching<br />

Reverse HTTPS proxy configuration 3<br />

Optional settings for a reverse HTTPS proxy configuration<br />

In addition to configuring the network setup and the SSL certificate handling, you can complete some<br />

optional activities to ensure the smooth operation of a reverse HTTPS proxy configuration:<br />

• Deactivate proxy loop detection<br />

• Restrict access to appliance ports<br />

• Restrict access to web servers<br />

• Address multiple web servers<br />

Deactivate proxy loop detection<br />

The appliance can detect proxy loops by evaluating the Via header of a client request. It is<br />

recommended that you deactivate this detection process in a reverse HTTPS proxy configuration.<br />

1 Go to Configuration | Appliances.<br />

2 On the appliances tree, go to the appliance you want to deactivate proxy loop detection for and select<br />

Proxies (HTTP(S), FTP, ICAP, and IM).<br />

3 In the Advanced Settings section, deselect HTTP(S): Inspect Via header to detect proxy<br />

loops.<br />

4 Click Save Changes.<br />

Restrict access to appliance ports<br />

In a reverse HTTPS proxy configuration, access should be restricted to the proxy ports of the appliance.<br />

You need to configure the user interface and file server settings accordingly.<br />

1 Go to Configuration | Appliances.<br />

2 On the appliances tree, go to the appliance you want to restrict port access for and select User<br />

Interface.<br />

3 Under HTTP Connector Port, enter the appliance proxy port (default: 9090).<br />

4 Select File Server.<br />

5 Under HTTP Connector Port, enter the appliance proxy port (default: 9090).<br />

6 Click Save Changes.<br />

Restrict access to web servers<br />

The purpose of a reverse HTTPS proxy configuration is to protect a limited number of particular web<br />

servers against unwanted data uploads. For this configuration, you should therefore allow access to<br />

these servers only and block it for others. After access to others servers has been requested and<br />

blocked, it is also recommended that you let the appliance close these connections.<br />

To implement this you need to:<br />

• Create a list of the web servers you want to protect<br />

• Create a rule set for a blocking rule<br />

• Create a rule that blocks access to other web servers and closes connections to clients after blocking<br />

their requests<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 65

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!