Cisco Ironport Asyncos 6.5.0 for Web User Guide
Total Page:16
File Type:pdf, Size:1020Kb
™ IronPort AsyncOS 6.5 USER GUIDE for Web Security Appliances COPYRIGHT Copyright © 2010 by IronPort Systems®, Inc. All rights reserved. Part Number: 421-0172 Revision Date: September 15, 2010 The IronPort logo, IronPort Systems, SenderBase, and AsyncOS are all trademarks or registered trademarks of IronPort Systems, Inc. All other trademarks, service marks, trade names, or company names referenced herein are used for identification only and are the property of their respective owners. This publication and the information contained herein is furnished “AS IS” and is subject to change without notice. Publication of this document should not be construed as a commitment by IronPort Systems, Inc. IronPort Systems, Inc., assumes no responsibility or liability for any errors or inaccuracies, makes no warranty of any kind with respect to this publication, and expressly disclaims any and all warranties of merchantability, fitness for particular purposes and non-infringement of third-party rights. Some software included within IronPort AsyncOS is distributed under the terms, notices, and conditions of software license agreements of FreeBSD, Inc., Stichting Mathematisch Centrum, Corporation for National Research Initiatives, Inc., and other third party contributors, and all such terms and conditions are incorporated in IronPort license agreements. The full text of these agreements can be found at https://support.ironport.com/3rdparty/AsyncOS_User_Guide-1- 1.html. Portions of the software within IronPort AsyncOS is based upon the RRDtool with the express written consent of Tobi Oetiker. IRONPORT SYSTEMS®, INC. CONTACTING IRONPORT CUSTOMER SUPPORT IronPort Systems, Inc. If you have purchased support directly from IronPort Systems, you 950 Elm Ave. can request our support by phone, email or online 24 hours a day, 7 San Bruno, CA 94066 days a week. During our office hours (24 hours per day, Monday through Friday excluding US holidays), one of our engineers will contact you within an hour of your request. To report a critical issue that requires urgent assistance outside of our office hours, please call us immediately at the numbers below. U.S. Toll-free: 1 (877) 641-4766 International: http://cisco.com/web/ironport/contacts.html Support Portal: http://www.cisco.com/cisco/web/support/index.html If you have purchased support through a reseller or another entity, please contact them for support of your IronPort products. Table of Contents 1. Getting Started with the Web Security Appliance . 1 What’s New in This Release . 2 New Feature: FIPS Compliance. 2 What’s New in Version 6.3 . 3 New Feature: Rich Acceptable Use Controls with URL Filtering . 3 What’s New in Version 6.0 . 4 New Feature: IronPort Data Security. 4 New Feature: External Data Loss Prevention . 4 New Feature: Native FTP . 5 New Feature: Multiple Identities in a Policy Group. 5 New Feature: Warning Users Before Continuing. 5 Enhanced: Authentication. 5 Enhanced: Logging . 7 Enhanced: Accelerated AsyncOS Upgrades . 8 How to Use This Guide . 9 Before You Begin . 9 Typographic Conventions . 10 Where to Find More Information . 10 IronPort Welcomes Your Comments . 12 Web Security Appliance Overview. 13 2. Using the Web Security Appliance . 15 How the Web Security Appliance Works . 16 Web Proxy . 16 The L4 Traffic Monitor . 16 Administering the Web Security Appliance . 17 System Setup Wizard . 17 Accessing the Web Security Appliance . 17 Using the Command Line Interface (CLI). 18 The SenderBase Network . 18 Reporting and Logging . 18 iii IRONPORT ASYNCOS 6.5 FOR WEB USER GUIDE Navigating the Web Security Appliance Web Interface . 19 Logging In . 21 Browser Requirements . 21 Monitor Tab. 21 Web Security Manager Tab . 22 Security Services Tab . 22 Network Tab . 23 System Administration Tab. 23 Committing and Clearing Changes . 25 Committing and Clearing Changes in the Web Interface . 25 Committing and Clearing Changes in the CLI. 26 3. Deployment. 27 Deployment Overview . 28 Preparing for Deployment . 28 Appliance Interfaces . 30 Management Interface . 30 Data Interfaces. 30 L4 Traffic Monitor Interfaces . 31 Example Deployment. 31 Deploying the Web Proxy in Explicit Forward Mode . 33 Configuring Client Applications . 33 Connecting Appliance Interfaces . 33 Testing an Explicit Forward Configuration . 33 Deploying the Web Proxy in Transparent Mode . 34 Connecting Appliance Interfaces . 34 Connecting the Appliance to a WCCP Router . 35 Configuring the Web Security Appliance . 35 Configuring the WCCP Router . 35 Example WCCP Configurations . 37 Working with Multiple Appliances and Routers . 39 Using the.