Secure Computing SSL Scanner Guia do Utilizador

Consulte online ou descarregue Guia do Utilizador para Software Secure Computing SSL Scanner. Secure Computing SSL Scanner User`s guide Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 150
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes

Resumo do Conteúdo

Página 1 - USER’S GUIDE

USER’S GUIDEWebwasher SSL ScannerVersion 6.0www.securecomputing.com

Página 2

IntroductionOtherwise, you could select a different filtering policy, using the drop-downlist.As you will have noticed, Advertising Filter is enabled,

Página 3 - Contents

CommonIt leaves the referer unaffected if you the user moves through the sameor subsequent path.This option may be enabled if user movement should be

Página 4 - User’s Guide

CommonCookie FilterThe Cookie Filter section looks like this:Using this section, you can configure a filter to block bad cookies.You can set the life

Página 5

CommonMake sure this radio button is checked if you want to configure a lifespan for neutral cookies. The radio button is checked by default.Enter the

Página 6 - What Else Will You Fin

Common3.8.2Cookie Filter ListThe Cookie Filter List tab looks like this:There is one section on the tab:• Cookie Filte r ListIt is described in the fo

Página 7 - Using Webwasher

CommonCookie Filter ListThe Cookie Filter List section looks like this:Using this section, you can add entries to the Cookie Filter List and edit them

Página 8 - First Level Tabs

CommonThe Cookie Filter List is displayed at the bottom of this section.To display only a particular number of list entries at a time, type this numbe

Página 9 - Configuring a Sample Setting

CommonTo do this, select a policy from the drop-down list labeled Policy, which is lo-cated above the Media Type Filters button:The options are arrang

Página 10

CommonText CategorizationThe Text Categorization section looks like this:Using the text categorization filter you can specify single keywords and comb

Página 11

Common3.9.2Categorization ListThe Categorization List tab looks like this:There is one section on this tab:• Text Catego rization ListIt is described

Página 12

CommonText Categorization ListThe Text Categorization List section looks like this:Using the text categorization filter you can specify single keyword

Página 13

Introduction1.3.3General Features of the Web InterfaceThis section explains a number features that are provided in the Web interfacefor solving genera

Página 14

CommonIn the input fields, enter the words or word combinations you want tofilter, e. g. Bahamas, Maledives, work tosetuparulelikethefol-lowing:Bahama

Página 15 - Other Documents

CommonUse the following items to perform other activities relating to the list:• FilterType a filter expression in this input field and enter it using

Página 16 - Introduction

Common3.10.1White ListThe White List tab looks like this:There is one section on this tab:• White ListIt is described in the following.3–58

Página 17

CommonWhite ListThe White List section l ooks like this:Using this section, you can add an object to the White List and exclude it fromthe application

Página 18 - The Webwasher Product Suite

CommonTo add an object to the white list, use the area labeled:• Add new entrySelect String or International Domain Name from the first of the drop-do

Página 19

CommonTo sort the list in ascending or descending order, click on the symbol next tothe Media Type or Description column heading.To edit an entry, typ

Página 20

Common3.11User Defined CategoriesThe User Defined Categories options are invoked by clicking on the corre-sponding button under Common:The options are

Página 21 - Chapter 2

CommonUser Defined CategoriesThe User Defined Categories section l ooks like this:Using this section, you can configure your own categories for URL cl

Página 22 - Overview (Feature)

Common• Category 1 to Category nIn the input fields provided here, enter the category names you want to useand the abbreviated formats of these names.

Página 23

Common3.12.1Media Type CatalogThe Media Type Catalog tab l ooks like this:There is one section on this tab:• Media Type CatalogIt is described in the

Página 24

IntroductionWhen you are attempting to leave a tab after modifying its settings, but withoutclicking on Apply Changes, an alert is displayed to remind

Página 25

CommonMedia Type CatalogThe Media Type Catalog section looks like this:Using this section, you can add a m edia type to the Media Type Catalog.A media

Página 26

CommonThe media type tells the application that receives the data what kind of appli-cation is needed to process the content, e. g. Real Audio is to p

Página 27

Common— Magic BytesIn the input fields provided here, enter up to five magic byte sequencesand their offsets to identify a media type:OffsetIn the inp

Página 28

Chapter 4SSL ScannerThe features that are described in this chapter are accessible over the SSLScanner tab of the Web interface:These features allow y

Página 29 - Feedback

SSL Scanner4.1OverviewThe following overview shows the sections that are in this chapter:User’s Guide SSL ScannerIntroductionHomeCommonSSL Scanner Ove

Página 30

SSL ScannerTo do this, select a policy from the drop-down list labeled Policy, which is lo-cated above the Certificate Verification button:The options

Página 31 - Feedback Queues

SSL ScannerFurthermore, there is this section on the tab:• Certificate VerificationIt is described in the following.Certificate VerificationThe Certif

Página 32

SSL ScannerIf the Common Name in a certificate is, e. g. abcde.com, but the Webserver’sURLisinfactwww.abcde.com, no match is achieved.• Wildcard match

Página 33

SSL ScannerTo do this, select a policy from the drop-down list labeled Policy, which is lo-cated above the Certificate Verification button:The options

Página 34

SSL ScannerTunneling by CategoryThe Tunneling by Category section looks like this:Using this section, you c an configure tunneling for particular URL

Página 35

IntroductionInformation UpdateSome parts of the information that is provided on the tabs of the Web interfacewill change from time to time. In these c

Página 36 - Malware Feedback Black List

SSL Scanner— Bypass SSL ScannerThe SSL Scanner is bypassed completely, i. e. no activities whatso-ever are performed.Client Certificate HandlingThe Cl

Página 37

SSL Scanner• Verify server certificate, but do not decrypt sessionEnable this option, to have the s erver certificate checked by the verificationproce

Página 38

SSL Scanner4.4Certificate ListThe Certificate L ist options are invoked by clicking on the corresponding but-ton under SSL Scanner:If you want to enab

Página 39

SSL Scanner4.4.1Certificate ListThe Certificate List tab looks like this:There is one section on this tab:• Certificate ListIt is described in the fol

Página 40

SSL ScannerTo add an exception to the list, use the area labeled:• Add new exceptionIn the input field provided here, enter the exception you want to

Página 41

SSL Scanner— by hostEnabling the by host method means that the host is checked without acertificate being included in the verification process. If the

Página 42

SSL ScannerIf the number of entries is higher than this number, the remaining entries areshown on successive pages. A page indicator is then displayed

Página 43 - Additional Documentation

SSL Scanner4.5.1Trusted Certificate AuthoritiesThe Trusted Certificate Authorities tab looks like this:At the top of this tab, there is the Known Cert

Página 44 - Preferences

SSL ScannerUsing this section, you can configure actions for content with certificates issuedby known Certificate Authorities (CAs) that are either tr

Página 45

SSL ScannerTrusted Certificate A uthoritiesThe Trusted Certificate Authorities section looks like this:This section provides the list of Trusted Certi

Página 46

IntroductionSearchA Search input field and button are located in the top right corner of the Webinterface area.Using these, you can start keyword quer

Página 47

SSL ScannerTo make the addition valid for all policies, mark the checkbox labeled Addto all policies before proceeding any further.Then click on eithe

Página 48

SSL Scanner4.6Global C ertificate ListThe Global Certificate List options are invoked by clicking on the corre-sponding button under SSL Scanner:If yo

Página 49 - Information

SSL ScannerThere is one section on this tab:• Global Certificate ListIt is described in the following.Global Certificate ListThe Global Certificate Li

Página 50

SSL ScannerFor the meaning of these actions, see the following table:by certificate by hostAllow Theexceptionisallowed. not availableBlock The excepti

Página 51

SSL ScannerFor the meaning of these actions, see the description of the by cer-tificate method above.A message will then be displayed, stating if the

Página 52 - Notification

SSL Scanner4.7Global Trusted Certificate AuthoritiesThe Global Trusted Certificate Authorities options are invoked by clickingon the corresponding but

Página 53

SSL ScannerTrusted Certificate A uthoritiesThe Trusted Certificate Authorities section looks like this:This section provides the global list of Truste

Página 54 - %o FQDN na me of the host

SSL ScannerIf the number of entries is higher than this number, the remaining entries areshown on successive pages. A page indicator is then displayed

Página 55 - Chapter 3

SSL ScannerThey are described in the upcoming section:• Incident Manager, see 4.8.14.8.1Incident ManagerThe Incident Manager tablookslikethis:There is

Página 56 - MediaTypeFilters

SSL ScannerUsing this section, you can inspect and manage incidents relating to SSL-en-crypted communication.The Incident Manager enables you to retri

Página 57

IntroductionAfter modifying the interval specified there, click on Apply Changes to makethis setting effective.Clicking OK will redirect you to the lo

Página 58

SSL ScannerA list entry consists of the following fields:• Host - URL that caused the incident.Incidents can be added to the certificate lists either

Página 59

Introduction1.4.1Documentation on Main ProductsThis section introduces the user documentation on the main products of Web-washer.Document Group Docume

Página 60

Introduction1.4.2Documentation on Special ProductsThis section introduces the user documentation on products for special tasksand environments.Documen

Página 61 - Media Type Black List

Introduction1.5The Webwasher Product SuiteThe Webwasher suite of products provides an optimal solution for all your se-cure content management needs.I

Página 62

IntroductionThe following two products have their own user interfaces, which are describedin the corresponding guides, see also 1.4.2.Webwasher®Conten

Página 63

Part Number: 86-0946227-BAll Rights Reserved, Published and Printed in G erma ny©2006 Secure Computing Corporation. This document may not, in whole or

Página 65

Chapter 2HomeThe features that are described in this chapter are accessible over the Hometab of the Web interface:These are basic features that are co

Página 66

Home2.1OverviewThe following overview shows the sections that are in this chapter:User’s Guide SSL ScannerIntroductionHome Overview –thissectionOvervi

Página 67 - Document Inspector

Home2.2.1Overview (Feature)The Overview tab looks like this:There are four sections on this tab:• System Alerts• System Summary• One-Click Lockdown• V

Página 68

HomeSystem AlertsThe System Alerts section looks like this:This section displays alerts to make you aware of problems concerning thesystem s tatus. Th

Página 69

HomeSystem SummaryThe System Summary section looks like this:This section d isplays information on the system status.Information is provided on the us

Página 70

HomeTo enable the emergency mode:• Click on the Activate emergency mode button.This button is a toggle s witch. After enabling the emergency mode, the

Página 71

Home2.3SupportThe Support options are invoked by clicking on the corresponding button un-der Home:The options are arranged under the following tab:The

Página 72

HomeSupportThe Support section looks like this:Using this section, you can contact the Webwasher support team.The section provides a number of buttons

Página 73 - Archive Handler

Home2.4FeedbackThe Feedback options are invoked by clicking on the c orresponding buttonunder Home:The options are arranged under the following tabs:T

Página 74

ContentsChapter 1 Introduction ... 1– 11.1 About This Guide...

Página 75

Home2.4.1FeedbackThe Feedback tab looks like this:There are two sections on this tab:• Feedback E-Mail Address• URL Filter Database FeedbackThey are d

Página 76 - Generic Header Filter

HomeURL Filter Database FeedbackThe URL Filter Database Feedba ck section looks like this:Using this section, you can submit unclassified or incorrect

Página 77

HomeThere are three sections on this tab:• Spam False Positives Feedback Queue• Spam False Negatives Feedback Queue• Malware Feedback QueueThey are de

Página 78

HomeThe default interval is 240 minutes. Entering 0 here means that no e-mailswill be sent automatically.E-mails can be sent manually, however, using

Página 79 - Generic Body Filter

Home• Send interval in . . . minutesIn the input field provided here, enter a time interval (in minutes) to specifythe time that is to elapse between

Página 80

HomeUse the following items to configure the malware feedback:• SMTP queue to useFrom this drop-down list, select an e-mail queue. E-mails and small d

Página 81

Home2.4.3Malware Feedback Black ListThe Malware Feedback Black List tab looks like this:There is one section on this tab:• Malware Feedback Media Type

Página 82 - Advertising Filters

HomeUsing this section, you can add a media type to the Media Type Black List formalware feedback. Objects belonging to the media types on this list w

Página 83

HomeUse the following items to perform other activities relating to the list:• FilterType a filter expression in the input field of the Media Type or

Página 84

Home2.5.1Documentation on Main ProductsThe DocumentationonMainProductstab looks like this:There are three sections on this tab:• General Documents• Pr

Página 85

User’s Guide3.6 Generic Body Filter ... 3–253.6.1 Generic Body Filter...

Página 86

HomeTo view any of the documents listed here, click on the PDF link in the sameline. This will open a .pdf format version of the document.Product Docu

Página 87

Home2.5.2Documentation on Special ProductsThe Documentation on Special Products tab looks like this:There are four sections on this tab:• Content Repo

Página 88

HomeInstant Message Filter DocumentsThe Instant Message Filter Documents section looks like this:This section allows you to v iew user documentation o

Página 89

HomeTo view any of the documents listed here, click on the PDF link in the sameline. This will open a .pdf format version of the document.2.5.3Additio

Página 90

Home2.6PreferencesThe Preferences options are invoked by clicking on the corresponding buttonunder Home:The options are arranged under the following t

Página 91 - Link Filter List

HomeThey are described in the following.Change PasswordThe Change Password section looks like this:Using this section, you can change the password you

Página 92

HomeIf you are only interested in viewing and configuring settings for Web traffic,you can hide the e-mail related settings and vice versa.Furthermore

Página 93

HomeTo what extent you are allowed to configure access permissions for other ad-ministrators, depends on your seniority level. This is measured by a v

Página 94 - Dimension Filter List

Home— Allow read o nly accessCheck this radio button to allow read only access.• Deny simultaneous accessCheck this radio button to deny simultaneous

Página 95

Home2.7.1InformationThe Information tablookslikethis:There are four sections on this tab:• License Information• Webwasher End User License Agreement•

Página 96

Chapter 1IntroductionWelcome to the Webwasher® User’s G uide SSL Scanner. It provides you withthe information needed to configure and use the SSL Scan

Página 97 - Privacy Filters

HomeLicense InformationThe License Information section looks like this:This section displays information regarding the license of the Webwasher soft-w

Página 98

HomeTo import a license, proceed as follows:1. Click on the Browse button provided here and browse for the license fileyou want to import.Before you c

Página 99

Home2.7.2NotificationThe Notification tab looks like this:There are two sections on this tab:• System Notifications• Too Many ClientsThey are describe

Página 100

HomeAfter specifying the appropriate information, click on Apply Changes to makeyour settings effective.Use the following items to configure the syste

Página 101

HomeUsing this section, you can configure messages to be written to the system logif connections were refused due to heavy work load or license exhaus

Página 102

Chapter 3CommonThe features that are described in this chapter are accessible over the Com-mon tab of the Web interface:These are filtering features t

Página 103 - Cookie Filter List

Common3.1OverviewThe following overview shows the sections that are in this chapter:User’s Guide SSL ScannerIntroductionHomeCommon Overview –thissecti

Página 104

CommonTo do this, select a policy from the drop-down list labeled Policy, which is lo-cated above the Media Type Filters button:The options are arrang

Página 105 - Text Categorization

CommonMedia Type FilterThe Media Type Filter section looks like this:Using this section, you can configure actions, e. g. Block, Block, log andnotify,

Página 106 - Settings

Common• Non-rectifiable media types with magic bytes mismatchThe actions configured here will be executed when content types do notmatch their magic b

Página 107

Introduction1.1About This GuideThe following overview lists the chapters of this guide and explains briefly whatthey are about:User’s Guide SSL Scanne

Página 108 - Categorization List

CommonFurthermore, you need to enable an option on the REQMOD Settings tab touse this filter. To do this, click on the REQMOD Settings link provided a

Página 109

Common3.2.2Media Type Black ListThe Media Type Black List tablookslikethis:There is one section on this tab:• Media Type Black ListIt is described in

Página 110

CommonMedia Type Black ListThe Media Type Black List section looks like this:Using this section, you can add a media type to the Media Type Black List

Página 111 - White List

CommonAfter s electing a media type, click on this button to add it to the list.This addition will be valid only under the policy you are currently co

Página 112

Common3.2.3Media Type White ListThe Media Typ e White List tab looks like this:There is one section on this tab:• Media Type White ListIt is described

Página 113

CommonMedia Type White ListThe Media Type White List section l ooks like this:Using this section, you can add a media type to the Media Type White Lis

Página 114

CommonThis addition will be valid only under the policy you are currently con-figuring.To add a media type to the white list for all policies, mark th

Página 115

Common3.3Document InspectorThe Document Inspector options are invoked by clicking on the correspond-ing button under Common:If you want to enable any

Página 116 - User Defined Categories

Common3.3.1Document InspectorThe Document Inspector tab looks like this:There are five sections on this tab:• Document Download Filter• Document Uploa

Página 117

CommonDocument Download FilterThe Document Download Filter section looks like this:Using this section, you can configure actions for inbound office do

Página 118 - Media Type Catalog

Introduction1.3Using WebwasherA user-friendly, task-oriented Web interface has been designed for accessingthe features of the Webwasher products. It l

Página 119

CommonDocument Upload FilterThe Document Upload Filter section looks like this:Using this section, you can configure actions for outbound user-origina

Página 120

CommonThis active content may be hostile rather than friendly, so for full protectionagainst files that are embedded into Microsoft Office or PDF docu

Página 121

CommonUse the following checkboxes to modify the assignment of filters to documentformats:• Download FilterMark or clear the checkboxes in this line t

Página 122

Common• Structured Storage document, like Visio or MSI, not readableFrom the drop-down lists provided here, select actions for documents inWeb and e-m

Página 123 - SSL Scanner

CommonTo do this, select a policy from the drop-down list labeled Policy, which is lo-cated above the Media Type Filters button:The options are arrang

Página 124 - Certificate Verification

CommonArchive HandlingThe Archive Handling section looks like this:Using this section, you can configure blocking and other actions for encrypted,corr

Página 125

CommonUsing this section, you can configure limits for archive sizes and recursionlevels.After specifying the appropriate settings click on Apply Chan

Página 126

Common3.5.1Generic Header FilterThe Generic Header Filter tab looks like this:There is one section on this tab:• Header Filter ListIt is described in

Página 127 - Scan Encrypted Traffic

CommonHeader Filter ListThe Header Filter List section looks like this:Using this section, you can configure the Generic Header Filter to delete head-

Página 128

Common3.6Generic Body FilterThe Generic Body Filter options are invoked by clicking on the correspondingbutton under Common:If you want to enable any

Página 129

Introduction1.3.1First Level TabsThe Web interface displays a number of tabs and sections for configuring thefeatures provided by Webwasher. On the to

Página 130

Common3.6.1Generic Body FilterThe Generic Body Filter tab looks like this:There is this section on this tab:• Body Filter ListIt is described in the f

Página 131

CommonBody Filter ListThe Body Filter List section looks like this:Using this section, you can configure the Generic Body Filter blocking andother act

Página 132 - Certificate List

CommonSo, to block, e. g. all HTML pages encoded as UTF-16 you can configure arule like the following:0-128 Contains I"<\00h\00t\00m\00l\00&qu

Página 133

Common• Dimension Filter List, see 3.7.33.7.1SettingsThe Settings tab looks like this:There are six sections on this tab:• Link Filter• Dimension Filt

Página 134

CommonThey are described in the following.Link FilterThe Link Filter section looks like this:Using this section, you can configure the filtering of co

Página 135

Common— WindowsEnables or disables the filtering of windows, which are also commonlyknown as pop-ups.A pop-up is a display area, usually a small windo

Página 136

CommonA text link is the grouping of linked text that, when clicked on, takesyou to another page either within the same Web site, or to an entirelydif

Página 137

Common— AppletsEnables or disables the filtering of Java applets.These are small programs accompanying a Web page that is sent to auser. Java applets

Página 138

CommonScript FilterThe Script Filter section looks like this:Using this section, you can configure a filter to manage the code that manipu-lates brows

Página 139

CommonAnimation FilterThe Animation Filter section looks like this:Using this section, you can configure a filter to detect animated images. Ani-matio

Página 140

Introduction1.3.2Configuring a Sample SettingThis section explains how to configure a s ample setting of a Webwasher fea-ture. The feature chosen here

Página 141 - Global C ertificate List

CommonAdvertising Filter SettingsThe Advertising Filter Settings section looks like this:Using this section, you can configure settings that will appl

Página 142

CommonThen check the radio buttons below to further specify the exclusion:— the same pathEnable this option to exclude objects within the s ame place

Página 143

CommonLink Filter ListThe Link Filter List section looks like this:Using this section, you can add URLs to the Link Filter List and edit them.To do th

Página 144

Common— do not filterEnable this option to exclude the URL you entered above from filtering.— Add to Li n k Filter ListAfter specifying the informatio

Página 145

Common3.7.3Dimension Filter ListThe Dimension Filter List tab looks like this:There is this one section on this tab:• Dimension Filter ListIt is descr

Página 146

CommonDimension Filter ListThe Dimension Filter List section looks like this:Using this section, you can add dimension settings to the Dimension Filte

Página 147 - Incident Manager

Common— Add to Dimension Filter ListAfter specifying the dimensions settings in the w ay described above,click on this button to add them to the list.

Página 148

Common3.8Privacy FiltersThe Privacy Filters options are invoked by clicking on the corresponding but-ton under Common:If you want to enable any of the

Página 149

Common3.8.1SettingsThe Settings tab looks like this:There are four sections on this tab:• Web Bug Filter• Referer Filter• Prefix Filter• Cookie F ilte

Página 150

CommonUsing this section, you can configure a filter to eliminate Web bugs.These are also known as clear GIFs or Web beacons. They are are usually1 pi

Comentários a estes Manuais

Sem comentários