Websense Content Gateway Online Help Version
Total Page:16
File Type:pdf, Size:1020Kb
Online Help Websense Content Gateway v7.6 Websense Content Gateway Online Help April, 2011 R033011760 Copyright © 1996-2011 Yahoo, Inc., and Websense, Inc. All rights reserved. This document contains proprietary and confidential information of Yahoo, Inc and Websense, Inc. The contents of this document may not be disclosed to third parties, copied, or duplicated in any form, in whole or in part, without prior written permission of Websense, Inc. Websense, the Websense Logo, ThreatSeeker and the YES! Logo are registered trademarks of Websense, Inc. in the United States and/or other countries. Websense has numerous other unregistered trademarks in the United States and internationally. All other trademarks are the property of their respective owners. Every effort has been made to ensure the accuracy of this manual. However, Websense Inc., and Yahoo, Inc. make no warranties with respect to this documentation and disclaim any implied warranties of merchantability and fitness for a particular purpose. Websense Inc. shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice. Traffic Server is a trademark or registered trademark of Yahoo! Inc. in the United States and other countries. Red Hat is a registered trademark of Red Hat Software, Inc. Linux is a registered trademark of Linus Torvalds. Microsoft, Windows, Windows NT, and Active Directory are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. Mozilla and Firefox are registered trademarks of the Mozilla Foundation. Netscape and Netscape Navigator are registered trademarks of Netscape Communications Corporation in the United States and in other countries. UNIX is a registered trademark of AT&T. All other trademarks are property of their respective owners. RESTRICTED RIGHTS LEGEND Use, duplication, or disclosure of the technical data contained in this document by the Government is subject to restrictions as set forth in subdivision (c) (1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS 52.227-7013 and/or in similar or successor clauses in the FAR, or in the DOD or NASA FAR Supplement. Unpublished rights reserved under the Copyright Laws of the United States. Contractor/manufacturer is Websense, Inc, 10240 Sorrento Valley Parkway, San Diego, CA 92121. Portions of Websense Content Gateway include third-party technology used under license. Notices and attribution are included elsewhere in this manual. Contents Contents Topic 1 Overview . 1 TRITON Unified Security Center . 2 Deployment options . 3 As a Web proxy cache. 3 In a cache hierarchy. 3 In a managed cluster . 3 As an SSL server. 4 As a DNS proxy cache . 4 Components . 5 Cache. 5 RAM cache . 5 Adaptive Redirection Module . 5 Host database. 5 DNS resolver. 6 Processes . 6 Administration tools . 7 Proxy traffic analysis features . 7 Online Help . 8 Technical Support. 8 Topic 2 Getting Started . 11 Starting Content Gateway Manager . 11 Entering your subscription key. 12 Providing system information . 13 Verifying that the proxy is processing Internet requests . 14 Using the command-line interface . 14 Starting and stopping Content Gateway on the Command Line . 15 Topic 3 Web Proxy Caching . 17 Cache requests . 17 Ensuring cached object freshness . 18 HTTP object freshness . 18 FTP object freshness . 22 Scheduling updates to local cache content . 22 Configuring the Scheduled Update option . 23 Forcing an immediate update . 24 Pinning content in the cache. 24 Setting cache pinning rules . 25 Enabling cache pinning . 25 To cache or not to cache? . 25 Online Help i Contents Caching HTTP objects . 25 Client directives . 26 Origin server directives . 27 Configuration directives . 29 Forcing object caching . 31 Caching HTTP alternates . 31 Configuring how Content Gateway caches alternates. 31 Limiting the number of alternates for an object . 32 Caching FTP objects. 32 Disabling FTP over HTTP caching. 33 Topic 4 Explicit Proxy Caching . 35 Manual browser configuration . 35 Using a PAC file. 36 Sample PAC file . 37 Using WPAD . 38 Configuring FTP clients in an explicit proxy environment . 39 Topic 5 Transparent Proxy and ARM . 43 Enabling the ARM . 44 Transparent interception strategies . 45 Transparent interception with a Layer 4 switch . 45 Transparent interception with WCCP v2 devices . 46 Transparent interception and multicast mode . 59 Transparent interception with policy-based routing . 60 Transparent interception with software-based routing . 60 Interception bypass . 61 Dynamic bypass rules . 62 Static bypass rules . 63 Viewing the current set of bypass rules . 64 Connection load shedding . 64 Reducing DNS lookups . 65 IP spoofing . 66 IP spoofing and the flow of traffic . 66 Enabling IP spoofing: . 68 Topic 6 Clusters. 69 Management clustering . 70 SSL Manager clustering . 70 Configuring SSL Manager clustering: . 71 Changing clustering configuration . 72 Adding nodes to a cluster . 72 Deleting nodes from a cluster . 74 ii Websense Content Gateway Contents Virtual IP failover. 74 What are virtual IP addresses? . 75 Enabling and disabling virtual IP addressing . 75 Adding and editing virtual IP addresses . 76 Topic 7 Hierarchical Caching . 77 HTTP cache hierarchies . ..