Novell Bordermanager 3.9 Administration Guide Novdocx (ENU) 29 January 2007
Total Page:16
File Type:pdf, Size:1020Kb
Novell BorderManager 3.9 Administration Guide novdocx (ENU) 29 January 2007 January 29 (ENU) novdocx Novell BorderManager 3.9 www.novell.com ADMINISTRATION GUIDE April 5, 2007 novdocx (ENU) 29 January 2007 January 29 (ENU) novdocx Legal Notices Novell, Inc. makes no representations or warranties with respect to the contents or use of this documentation, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Further, Novell, Inc. reserves the right to revise this publication and to make changes to its content, at any time, without obligation to notify any person or entity of such revisions or changes. Further, Novell, Inc. makes no representations or warranties with respect to any software, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Further, Novell, Inc. reserves the right to make changes to any and all parts of Novell software, at any time, without any obligation to notify any person or entity of such changes. Any products or technical information provided under this Agreement may be subject to U.S. export controls and the trade laws of other countries. You agree to comply with all export control regulations and to obtain any required licenses or classification to export, re-export or import deliverables. You agree not to export or re-export to entities on the current U.S. export exclusion lists or to any embargoed or terrorist countries as specified in the U.S. export laws. You agree to not use deliverables for prohibited nuclear, missile, or chemical biological weaponry end uses. See the Novell International Trade Services Web page (http://www.novell.com/info/exports/) for more information on exporting Novell software. Novell assumes no responsibility for your failure to obtain any necessary export approvals. Copyright © 1997-2007 Novell, Inc. All rights reserved. No part of this publication may be reproduced, photocopied, stored on a retrieval system, or transmitted without the express written consent of the publisher. Novell, Inc. has intellectual property rights relating to technology embodied in the product that is described in this document. In particular, and without limitation, these intellectual property rights may include one or more of the U.S. patents listed on theNovell Legal Patents Web page (http://www.novell.com/company/legal/patents/) and one or more additional patents or pending patent applications in the U.S. and in other countries. Novell, Inc. 404 Wyman Street, Suite 500 Waltham, MA 02451 U.S.A. www.novell.com Online Documentation: To access the latest online documentation for this and other Novell products, see the Novell Documentation Web page (http://www.novell.com/documentation). novdocx (ENU) 29 January 2007 January 29 (ENU) novdocx Novell Trademarks For Novell trademarks, see the Novell Trademark and Service Mark list (http://www.novell.com/company/legal/ trademarks/tmlist.html). Third-Party Materials All third-party trademarks are the property of their respective owners. novdocx (ENU) 29 January 2007 novdocx (ENU) 29 January 2007 January 29 (ENU) novdocx Contents About This Guide 11 Part I Proxy 13 1 Proxy Services Prerequisites 15 1.1 Setting Up the DNS Resolver . 15 1.2 Configuring Web Browsers to Use Novell BorderManager . 16 1.2.1 Setting Up Mozilla Firefox to Use a Web Proxy. 16 1.2.2 Setting Up Microsoft Internet Explorer to Use a Web Proxy . 18 1.2.3 Setting Up Netscape Navigator to Use a Web Proxy . 18 2 Configuring Proxy Services 19 2.1 Configuring Application Proxies. 19 2.1.1 Configuring an HTTP Proxy . 19 2.1.2 Configuring an FTP Proxy . 21 2.1.3 Configuring FTP Proxy in Active Mode . 22 2.1.4 Configuring a Mail Proxy . 22 2.1.5 Configuring RealAudio and RTSP Proxies . 24 2.1.6 Configuring a DNS Proxy . 24 2.1.7 Configuring a Generic TCP Proxy . 25 2.1.8 Configuring a Generic UDP Proxy. 26 2.2 Configuring Proxy Acceleration . 27 2.2.1 Configuring HTTP Acceleration. 27 2.2.2 Blocking Virus Requests in the HTTP Accelerator . 29 2.2.3 Configuring FTP Reverse Proxy . 32 2.3 Configuring Transparent Proxies . 33 2.3.1 Configuring an HTTP Transparent Proxy . 33 2.3.2 Configuring Telnet Transparent Proxy . 34 2.4 Configuring Authentication. 35 2.4.1 Configuring Proxy Authentication . 35 2.4.2 Configuring Terminal Server Authentication . 37 2.5 Configuring Session Failover. 38 2.5.1 Overview of Session Failover . 39 2.5.2 Configuring Session Failover . 43 2.6 Configuring the SOCKS V4 or V5 Gateway. 45 2.6.1 Configuring the SOCKS Server. 46 2.6.2 Configuring the SOCKS Client . 48 3 Advanced Proxy Configurations 49 3.1 Configuring Caching Hierarchies . 49 3.1.1 Configuring Cache Hierarchy Server. 49 3.1.2 Configuring Cache Hierarchy Client . 51 3.1.3 Configuring Cache Hierarchy Routing. 52 3.2 Configuring Cache Parameters . 53 3.2.1 Configuring Cache Aging Parameters. 53 3.2.2 Configuring Cache Control Parameters . 54 3.2.3 Configuring Cache Location Parameters . 55 Contents 5 novdocx (ENU) 29 January 2007 January 29 (ENU) novdocx 3.2.4 Configuring Cachable Object Control Parameters . 56 3.3 Configuring IP Addresses. 58 3.4 Configuring DNS Transport Parameters. 58 3.5 Configuring Transport Timeout Parameters . 59 4 Managing Proxy Services 61 4.1 Configuring Proxy Logging . 61 4.1.1 Configuring Logging for an HTTP Proxy . 61 4.1.2 Configuring Logging for an HTTP Accelerator . 62 4.2 Monitoring Proxy Statistics . 63 4.2.1 Monitoring Proxy Cache Real-time Activity . 64 4.2.2 Monitoring HTTP Statistics. 64 4.2.3 Monitoring FTP Statistics . 65 4.2.4 Monitoring Mail (SMTP/POP3) Statistics . 66 4.2.5 Monitoring Gopher Statistics . 67 4.2.6 Monitoring RealAudio Statistics . 68 4.2.7 Monitoring SOCKS Statistics . 69 4.2.8 Monitoring Generic Statistics . 69 4.2.9 Monitoring ICP Statistics . 70 4.2.10 Monitoring Client FTP Statistics . 70 4.3 Monitoring Cache Statistics . 71 4.3.1 Monitoring General Cache Statistics . 71 4.3.2 Monitoring DNS Cache Statistics . 72 4.3.3 Monitoring Connection Cache Statistics . 73 4.3.4 Monitoring Download Cache Statistics. 74 4.4 Proxy Configuration Dump Tool . 74 4.5 Splash Screen Settings . 74 5 Using Novell Audit for HTTP Proxy Logging 75 5.1 Configuring Novell BorderManager for Novell Audit. 75 5.2 Understanding the Novell BorderManager Event Data . 76 5.3 Viewing Events in Novell Audit Report . 77 5.4 Configuring the Audit Server . 78 6 Configuring Access Rules 79 6.1 Configuring a Rule to Allow.