BI.Ue Coat Certified Proxysg Administrator Course
Total Page:16
File Type:pdf, Size:1020Kb
BlueOCoat Secure and Acceerate Your Business a BI.ue Coat Certified ProxySG Administrator Course version 3.5.1 Student Textbook Accelerating Business Applications www. b u e coat .com BlueTouch Training Services — BCCPA Course v3.5.1 Contact Information Blue Coat Systems Inc. 410 North Mary Avenue Simnyvale, California 94085 North America (USA) Toll Free: +1.866.302.2628 (866.30.BCOAT) North America Direct (USA): +1.408.220.2200 Asia Pacific Rim (Hong Kong): +852.2166.8121 Europe, Middle East, and Africa (United Kingdom): +44 (0) 1276 854 100 [email protected] [email protected] www.bluecoat.com Copyright ©1999-2011 Blue Coat Systems, Inc. All rights reserved worldwide. No part of this document may be reproduced by any means nor translated to any electronic medium without the written consent of Blue Coat Systems, Inc. Specifications are subject to change without notice. Information contained in this document is believed to be accurate and reliable, however, Blue Coat Systems, Inc. assumes no responsibility for its use. Blue Coat, ProxySG, PacketShaper, CacheFlow, IntelligenceCenter and BlueTouch are registered trademarks of Blue Coat Systems, Inc. in the U.S. and worldwide. All other trademarks mentioned in this document are the property of their respective owners. July 2011 r Table of Contents Course Introduction .1 Chapter 1: Blue Coat Product Family 3 Chapter 2: ProxySG Fundamentals 29 Chapter 3: ProxySG Deployment 37 Chapter 4: ProxySG Licensing 53 Chapter 5: ProxySG Initial Setup 63 Chapter 6: ProxySG Management Console 71 Chapter 7: Services 89 Chapter 8: Hypertext Transfer Protocol 105 Chapter 9: Policy Management 117 Chapter 10: WebPulse 133 Chapter 11: Authentication 149 Chapter 12: Authentication Using LDAP 163 Chapter 13: Creating Notifications and Exceptions 171 Chapter 14: Access Logging 181 Chapter 15: WAN Optimization Features 197 Chapter 16: Service and Support 209 Appendix A: Deployment Planning 219 Appendix B: Introduction to IPv6 227 Appendix C: Conditional Probability 231 III BlueTouch Training Services — BCCPA Course v3.5.1 iv Course Introduction The Blue Coat Certified ProxySG Administrator course is intended for students who wish to master the fundamentals of the Blue Coat ProxySG. It is designed for students who have not taken any previous training courses about the ProxySG. Students should be familiar with basic networking concepts, such as local-area networks (LANs), the Internet, security, and IP protocols. A basic knowledge of authentication methods is also a plus. After studying this course, you will understand: • Key concepts of network security and wide-area network (WAN) optimization. • The major functions of the ProxySG, how they work, and how to administer them. • How the ProxySG interfaces with other Blue Coat products. • How to get service and support from Blue Coat. By completing this course and passing an online exam, you can become a Blue Coat Certified Proxy Administrator. Applicable Software Versions This course is based on version 6.2 of the SGOS operating system that is used on the ProxySG. If your organization uses an earlier version of SGOS, some features described in this course might not work as described here, and the appearance and functionality of screens, menus, commands, and displays might be different from what you see here. Typographic Conventions • In this book, text appearing in this font generally is text that is part of a graphical user interface. This includes text in labels, names of buttons and menus, and Web page addresses that you type into a Web browser. • Text appearing in this font generally is text that is part of a command-line interface. This includes prompts, user input, and responses. This font also is used to show the content of some communication protocols, such as headers, commands, and data between a client and a server. • In both cases, text that appears in italics like this or like this represents text that you should replace with text specific to your deployment. For example, the URL https:IlproxylPaddr.8082 appears often in this book. In this example, the text proxylPaddr should be replaced with the actual four-octet numeric IP address of your ProxySG. BlueTouch Training Services — BCCPA Course v3.5.1 2 Chapter 1: Blue Coat Product Family In a connected world, the network is increasingly becoming a platform for collaboration bringing people together to share ideas, speed decision-making, and enhance competitiveness. Collaborative applications such as teleconferencing, unified communications, and social media are being deployed at an increasing rate. An increasingly capable wide area network combines with a host of regulatory mandates to drive infrastructure and data center consolidation, enabling enterprises to gain greater efficiencies, contain costs, and enhance agility. The key trends driving business today — centralization, mobilization, and globalization — often make it difficult, if not downright impossible, to support on-demand application delivery. IT initiatives such as server consolidation and voice, video, and data convergence can disrupt network service. Your mobile applications and devices can be compromised by security breaches and data theft. And global IT infrastructures often harbor data silos that are difficult to penetrate and manage, obscuring the view of your IT resources. Maintaining a sustainable competitive advantage in a rapidly changing business environment requires new levels of responsiveness. Access to information where, when, and how it is needed is critical to success. In today’s market, information is the currency of business. Delivering a superior user experience across corporate, branch, and remote locations depends on having: • The visibility to control what is running on the network. • The ability to accelerate business applications and meter recreational traffic. • The ability to do so in a safe and secure manner. Application Delivery Networks (ADNs) are emerging as an essential requirement in addressing these challenges. Blue Coat products provide an ADN infrastructure designed to optimize and secure the flow of information to any user, on any network, anywhere. After studying this chapter, you will understand: • The concepts of the Application Delivery Network. • How Blue Coat’s product family implements the ADN. • Basic features of each member of the Blue Coat product family. 3 BlueTouch Training Services — BCCPA Course v3.5.1 Application Delivery Network S Slide 1 —1: Application Delivery Network Implementing the Application Delivery Network answers the demand for greater application mobility and security in a changing global business environment. By combining three core capabilities — application performance monitoring (visibility), WAN optimization (acceleration), and Secure Web Gateway technologies (security) — the ADN helps you: • See applications and users and how they behave on the network. • Troubleshoot performance issues. — • Accelerate mission-critical applications, streaming video, SSL, and other enterprise applications. • Secure against malware, data leaks, and performance degradation. • Enable a highly efficient and productive end-to-end user experience anytime, anywhere. Visibility ¶ ii Blue Coat’s ADN solutions provide the ability to identify and classify applications and users across the network. You can discover all application traffic, monitor the user experience, troubleshoot performance issues and resolve problems before they impact the user experience. You can: — • Automatically discover more than 600 applications. • Identify peer-to-peer (P2P), recreational, and streaming applications over any port. • Subclassify complex applications such as SAP, Oracle, Citrix, Web, CIFS, MAPI, and DCOM. • Discover URLs and external sites within HTTP. • Identify problem hosts, servers, and applications. 1 4 [[i Chapter 1: Blue Coat Product Family Acceleration Blue Coat helps you accelerate business-critical applications, including internal, external, and real-time applications to any user, anywhere — all while ensuring a headquarters work experience, wherever your users are located. Acceleration technologies include: • Object and byte caching. • Compression and basic quality-of-service capabilities. • External Web and SSL acceleration. • Protocol acceleration for TCP, CIFS/NFS, MAPI, HTTP, and more. • Advanced Web policy and bandwidth management. • Advanced application ID technology. Security Blue Coat secures your Internet gateway to help protect users from malicious content and applications. Security capabilities include: • Anti-virus and maiware scanning. • Comprehensive data loss prevention. • URL and Web content filtering. • A centrally managed distributed gateway. • Granular policy management across more than 500 variables, including user, group, application, source, content types, and transaction. • Logging, statistics, and SNMP support. 5 BIueTouchTrairNng Services — BCCPA Course v3.5.1 Blue Coat Products BlueQCoat 3 P Slide 1 —2: Blue Coat products Blue Coat products provide total visibility and control over user and application performance — and fast, secure delivery of the critical applications that fuel business productivity. Proxy Technology • Blue Coat ProxySG: Delivers a scalable proxy platform architecture to secure Web communications and accelerate the delivery of business applications. The ProxySG is built on SGOS, a custom, object-based operating system that enables flexible policy control over content, users, applications, and protocols. The ProxySG is designed