﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>LevelBlue Knowledge Base » Knowledgebase » Legacy Products » Web Filter (R3000)</title><generator>InstantKB.NET 2.0.6</generator><description>LevelBlue Knowledge Base</description><link>https://support.levelblue.com/kb/</link><webMaster>website@m86security.com</webMaster><lastBuildDate>Tue, 21 Apr 2026 19:38:25 GMT</lastBuildDate><ttl>20</ttl><item><title>Where do I send a feature request for a LevelBlue Marshal product?</title><link>https://support.levelblue.com/kb/Goto12703.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;MailMarshal (SEG)&lt;/li&gt;    &lt;li&gt;MailMarshal ECM/MailMarshal Exchange&lt;/li&gt;    &lt;li&gt;MailMarshal SPE&lt;/li&gt;    &lt;li&gt;WebMarshal&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Where do I send a feature request for a LevelBlue Marshal product? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;If you want to request a new feature or you want to suggest an improvement for any product, you can &lt;a href="https://support.levelblue.com/contact-support.asp" class="ApplyClass" target="_blank"&gt;contact Technical Support&lt;/a&gt;. You can also enquire through your account manager or reseller.&lt;/p&gt;</description><pubDate>Sun, 01 Mar 2020 00:00:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>End-of-Life for Web Filter and WFR</title><link>https://support.levelblue.com/kb/Goto21103.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Trustwave Web Filter (WF)&lt;/li&gt;    &lt;li&gt;Trustwave Web Filtering and Reporting Suite (WFR)&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;As previously communicated, Trustwave Web Filter and WFR reached End-of-Life on September 1, 2019.&lt;/p&gt;&lt;p&gt;Patches and database updates are no longer provided for these products.&lt;/p&gt;&lt;p&gt;Customers can move to other Trustwave web filtering products:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;strong&gt;WebMarshal&lt;/strong&gt; (premises Windows software)&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Secure Web Gateway Cloud&lt;/strong&gt; (managed cloud service)&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Note that the Trustwave Security Reporter (SR) continues to be supported as a standalone device. However SR that was included in WFR is no longer supported.&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</description><pubDate>Thu, 26 Sep 2019 17:08:18 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>Web Filter Block Page Flow (Invisible Mode)</title><link>https://support.levelblue.com/kb/Goto20554.aspx</link><description>&lt;span id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;/span&gt;&lt;ul&gt;    &lt;li&gt;Web Filter &lt;/li&gt;    &lt;li&gt;Web Filter and Reporter &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question: &lt;/h2&gt;How does the Web Filter serves a block page to a client in Invisible Mode?&lt;h2&gt;Reply:&lt;/h2&gt;&lt;ol&gt;    &lt;li&gt;The &lt;strong&gt;Client&lt;/strong&gt; sends a request to a web site, which is also received by the &lt;strong&gt;Web Filter.&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;The &lt;strong&gt;Web Filter&lt;/strong&gt; sends a &lt;em&gt;TCP reset&lt;/em&gt; to both the &lt;strong&gt;Client&lt;/strong&gt; and the web site, so that the &lt;strong&gt;Client&lt;/strong&gt; doesn't keep requesting the web site, and the web site doesn't keep trying to serve to the &lt;strong&gt;Client.&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;The &lt;strong&gt;Web Filter&lt;/strong&gt; then sends an &lt;em&gt;HTTP 302 Redirect&lt;/em&gt; to the &lt;strong&gt;Client.&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;The &lt;strong&gt;Client&lt;/strong&gt; issues an &lt;em&gt;HTTP GET https://&amp;lt;ip_address&amp;gt;:81/block.cgi&lt;/em&gt; to the &lt;strong&gt;Web Filter.&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;The &lt;strong&gt;Web Filter&lt;/strong&gt; serves the &lt;strong&gt;Client&lt;/strong&gt; the block page. &lt;/li&gt;&lt;/ol&gt;&lt;img alt="" width="684" height="852" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/Block%20Page/WF_Block_page_flow%207.PNG" /&gt;&lt;ol&gt;&lt;/ol&gt;    &lt;p&gt; &lt;/p&gt;</description><pubDate>Fri, 10 Mar 2017 15:34:08 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>HTTPS Filtering and Block Pages</title><link>https://support.levelblue.com/kb/Goto12867.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;R3000 All Versions&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Why don't I get a block page when I am trying to access a blocked https site?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;Because of the nature of https connections it's often times not possible to send a block page to the end user after an HTTPS connection has been made with the website. The browser will not honor a TCP redirect from a secure website (the https site) to an unsecured website (the block page). The block page is only successfully delivered if the filter is able to send the redirect before the browser complete the TCP handshake with the website.&lt;/p&gt;&lt;p&gt;Instead of the Web Filter block page you will see an error message which will vary depending on the browser type.&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Mon, 30 Jan 2017 11:04:47 GMT</pubDate><dc:creator>Denton Diederich</dc:creator></item><item><title>X-Strike Blocking Custom Block Page </title><link>https://support.levelblue.com/kb/Goto14585.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WF &amp;amp; WFR&lt;/li&gt;    &lt;li&gt;version 5.1.05+&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;    &lt;p&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;    &lt;/span&gt;&lt;/p&gt;    &lt;p&gt;&lt;span&gt;Can a user being blocked via X-Strike Blocking be sent to a Custom Block Page URL&lt;/span&gt; &lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply: &lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;NO, it will need to be the ‘Default “Alternative” Locked Block Page’ option or else an Internal ‘Custom URL’ block page.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;System&amp;gt;X-Strike Blocking, Configuration tab, and Specify a Redirect URL &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If a public website is entered as a redirect URL, then the web site in question will automatically be excluded from the filter and not be logged.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;</description><pubDate>Wed, 21 Dec 2016 16:32:44 GMT</pubDate><dc:creator>Denton Diederich</dc:creator></item><item><title>Web Filtering and Reporting (WFR) Hardware Support Matrix</title><link>https://support.levelblue.com/kb/Goto14569.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;R3000 &lt;/li&gt;    &lt;li&gt;WFR/WF/SR &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;p&gt;Where can I find the current Trustwave Web Filtering and Reporting Hardware Support Matrix?&lt;/p&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;The current Trustwave Web Filtering and Reporting Hardware Support Matrix can be found in the attachment below. &lt;/p&gt;&lt;p&gt;This information was last updated in December 2016.&lt;/p&gt;</description><pubDate>Thu, 15 Dec 2016 12:57:44 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>Enabling SSH Password Authentication (Opening the Shell)</title><link>https://support.levelblue.com/kb/Goto20558.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I enable SSH password authentication for connection to a WebFilter server? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;h3&gt;&lt;/h3&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;NOTE:&lt;/strong&gt; In order to complete the following procedure, you must contact Trustwave Support and open a case to obtain the password needed in step 5.&lt;/em&gt;&lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;&lt;h3&gt;PART I – Shut Down and Connect a Keyboard and Monitor&lt;/h3&gt;&lt;p&gt; &lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Bring the system down: Navigate to&lt;strong&gt; System &amp;gt; Control&lt;/strong&gt;  and click &lt;strong&gt;ShutDown&lt;br /&gt;    &lt;/strong&gt; &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/shutdown_gui_1.png" /&gt; &lt;/li&gt;    &lt;li&gt;Click the&lt;strong&gt; ShutDown&lt;/strong&gt; button to power off the system.&lt;br /&gt;    &lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/shutdown_gui_resized_2.png" /&gt; &lt;/li&gt;    &lt;li&gt;Connect a monitor to the VGA port and the keyboard to a USB or PS/2 port on the back of the system:&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/rear_chassis_ports_1.png" /&gt; &lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;PART II – Single User Mode &lt;/h3&gt;&lt;ol start="4"&gt;    &lt;li&gt;Power up the system by pressing and holding the &lt;strong&gt;green check mark key&lt;/strong&gt; (located on the LCD panel on the front of the chassis) for &lt;em&gt;&lt;strong&gt;three seconds&lt;/strong&gt;&lt;/em&gt;. &lt;/li&gt;    &lt;li&gt;On the &lt;strong&gt;GNU GRUB&lt;/strong&gt; screen press &lt;strong&gt;p&lt;/strong&gt; to bring up the password dialog box, and enter in the password.&lt;br /&gt;    &lt;br /&gt;    &lt;strong&gt;NOTE:&lt;/strong&gt; &lt;em&gt;Please contact Trustwave Support and open a case to obtain the password.&lt;/em&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/grub_1.PNG" /&gt; &lt;/li&gt;    &lt;li&gt;Press &lt;strong&gt;e&lt;/strong&gt; to edit the entry.&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/grub_2.PNG" /&gt;&lt;br /&gt;    &lt;strong&gt; &lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Use the &lt;strong&gt;up arrow&lt;/strong&gt; and &lt;strong&gt;down arrow&lt;/strong&gt; keys to select the line that starts with ‘kernel’ and press &lt;strong&gt;e&lt;/strong&gt; to edit the line.&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/grub_3.PNG" /&gt;&lt;br /&gt;    &lt;strong&gt; &lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;At the end of this line, press the &lt;strong&gt;spacebar&lt;/strong&gt; to put in a space and type the word &lt;strong&gt;single&lt;/strong&gt; and then press &lt;strong&gt;enter&lt;/strong&gt;&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/grub_4.PNG" /&gt;&lt;br /&gt;    &lt;br /&gt;    &lt;br /&gt;    You should now be back to the previous screen. Press &lt;strong&gt;b&lt;/strong&gt; to boot into single-user mode.&lt;br /&gt;    &lt;br /&gt;    &lt;ol&gt;&lt;/ol&gt;        &lt;/li&gt;    &lt;/ol&gt;    &lt;h2&gt;&lt;/h2&gt;    &lt;h3&gt;PART III – Enable SSH Password Authentication&lt;/h3&gt;    &lt;ol start="9"&gt;        &lt;li&gt;At the prompt, type the command &lt;strong&gt;nano /etc/ssh/sshd_config&lt;/strong&gt; &lt;br /&gt;        &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/edit_pico_1.png" /&gt;&lt;br /&gt;        &lt;strong&gt; &lt;br /&gt;        &lt;/strong&gt;&lt;/li&gt;        &lt;li&gt;Use the arrow keys to find the line that says &lt;strong&gt;PermitRootLogin&lt;/strong&gt;*, and change it to &lt;strong&gt;yes&lt;/strong&gt;&lt;br /&gt;        &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/edit_2.PNG" /&gt;&lt;br /&gt;        &lt;br /&gt;        &lt;em&gt;*Note: this entry does not exist on all systems. If it is not present, skip to the next step.&lt;br /&gt;        &lt;/em&gt;  &lt;/li&gt;        &lt;li&gt;Use the arrow keys to find the line that says &lt;strong&gt;PasswordAuthentication&lt;/strong&gt;, and change it to &lt;strong&gt;yes&lt;/strong&gt;&lt;br /&gt;        &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/edit_3.PNG" /&gt; &lt;/li&gt;        &lt;li&gt;To save, press &lt;strong&gt;Ctrl&lt;/strong&gt;+&lt;strong&gt;x&lt;/strong&gt;, then press &lt;strong&gt;y&lt;/strong&gt;, and hit &lt;strong&gt;enter&lt;/strong&gt; &lt;/li&gt;        &lt;li&gt;Restart &lt;em&gt;sshd&lt;/em&gt; by running the command &lt;strong&gt;/etc/init.d/sshd restart&lt;/strong&gt;&lt;br /&gt;        &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/ssh_1.PNG" /&gt; &lt;/li&gt;        &lt;li&gt; You will see “Starting sshd” set to OK.&lt;br /&gt;        &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/ssh_2.PNG" /&gt; &lt;/li&gt;        &lt;li&gt;Press &lt;strong&gt;Ctrl&lt;/strong&gt;+&lt;strong&gt;d &lt;/strong&gt;to boot the system back up into multiuser mode.&lt;br /&gt;        &lt;br /&gt;        It will run through all of its checks, and bring you back to your logon screen.&lt;br /&gt;        &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/ssh_3.PNG" /&gt;&lt;br /&gt;        &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/ssh_4.PNG" /&gt; &lt;/li&gt;    &lt;/ol&gt;    &lt;h2&gt;&lt;/h2&gt;    &lt;h3&gt;Part IV - Test the Connection&lt;/h3&gt;    &lt;ol start="16"&gt;        &lt;li&gt;Open a terminal window or start a PuTTY session to verify that SSH is enabled from a device on the same network (not the filter). You can download PuTTY from &lt;a href="http://www.putty.org/"&gt;http://www.putty.org/&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;Enter &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;SSH [&lt;em&gt;Filter IP]&lt;/em&gt;&lt;/span&gt; (for example, &lt;span style="font-family: &amp;quot;courier new&amp;quot;;"&gt;SSH 10.10.10.11&lt;/span&gt; ). When prompted to continue connecting, type &lt;strong&gt;yes&lt;/strong&gt;. &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/ssh_5.PNG" /&gt; &lt;/li&gt;        &lt;li&gt;Enter any user name. If you are prompted for a password, then SSH has been successfully enabled. &lt;br /&gt;        &lt;br /&gt;        &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/rgrogan/SSH/ssh_6.PNG" /&gt; &lt;/li&gt;        &lt;li&gt;Repeat steps 1-4 to remove the monitor and keyboard, if necessary. &lt;/li&gt;    &lt;/ol&gt;</description><pubDate>Tue, 13 Dec 2016 15:48:33 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Alert Email: shadow.logs Pending</title><link>https://support.levelblue.com/kb/Goto12389.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;R3000 &lt;/li&gt;    &lt;li&gt;Web Filter 300/500/700&lt;/li&gt;    &lt;li&gt;WFR  350/550&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;p&gt;Alert Email: The hourly health check detects "shadow.log pending"! &lt;/p&gt;&lt;p&gt;This alert email represents an urgent issue and customers should contact Trustwave Support ASAP.&lt;/p&gt;&lt;h2&gt;Reply&lt;/h2&gt;&lt;p&gt;If the Web Filter is sending you an alert email stating that there are shadow.logs pending, it means that traffic log transfers to your Security Reporter or external FTP server are failing, if you have a &lt;strong&gt;WFR&lt;/strong&gt; or combo box where reporting is on the same hardware then call tech support now, some how the logs are not rotating to the reporter side.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background&lt;/strong&gt;: When a traffic log (shadow.log) transfer from the Filter fails, it keeps a copy of the log on its hard drive and attempts to send it again on the next log transfer session.  This will continue until the log is successfully transmitted.  Logs are transferred at the top of every hour.  If transfer failures continue to happen, the logs that fail to transfer will begin to build up, and this alert will be sent if 4 or more logs are failing to be sent. The filter will also show "failed" in Reporting&amp;gt;configuration&amp;gt;logs section. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Troubleshooting&lt;/strong&gt; &lt;strong&gt;a stand alone Reporter:&lt;/strong&gt; First verify if the reporter IP is responding to pings? if you ftp logs to a third-party-server verify if that server pings?&lt;/p&gt;&lt;p&gt;If the pings fail, please troubleshoot the reason why or call support, so we may log in and look.&lt;/p&gt;&lt;p&gt;There are a few possible causes for this error.  From the Web Filter GUI, go to the Reporting tab, and choose Report Configuration from the left.  Make sure that it is not trying to export to a device you do not have.  Also, verify that the addresses are correct in the settings for your export targets.  If everything looks ok, then click the "Log" tab and then the "View Log" button in order to see the FTP transfer logs. &lt;/p&gt;&lt;p&gt;If there are connection errors shown, then check your network connections to the export targets (&lt;em&gt;Reporter or FTP server, which ever is appropriate&lt;/em&gt;), as well as the status of these target devices (&lt;em&gt;Reporter or FTP server, whichever is appropriate&lt;/em&gt;).  If there are no visible error, but the PUT commands never seem to complete successfully, then the target device (&lt;em&gt;Reporter or FTP server, whichever is appropriate&lt;/em&gt;) may be full.  If the full target device is an Enterprise Reporter, contact Technical Support in order to resolve the issue. &lt;/p&gt;</description><pubDate>Wed, 28 Sep 2016 10:31:19 GMT</pubDate><dc:creator>Denton Diederich</dc:creator></item><item><title>Can I report on bandwidth per website?</title><link>https://support.levelblue.com/kb/Goto20547.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SR implementations reporting on Web Filter Data &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I run a report on bandwidth per website? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Response:&lt;/h2&gt;&lt;p&gt;Reporting on bandwidth per website is not available when reporting on Web Filter data. This function is only possible with an SWG/SR implementation. &lt;/p&gt;&lt;p&gt;Web Filter is not designed to report on the amount of bandwidth that was used. Web Filter can only report based on the information that is in the real time log. &lt;/p&gt;&lt;p&gt;The bandwidth category in the configuration of the Web Filter is referencing sites that are bandwidth intensive. If you are having issues with load on your network, you can block the bandwidth category to limit sites that are known to use large amounts of bandwidth. &lt;/p&gt;&lt;p&gt;For the SWG/SR implementation, instructions on how to report on bandwidth are available in the User Guide.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Fri, 01 Jul 2016 13:37:00 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>RMA Replacement Checklist - WF/WFR/SR</title><link>https://support.levelblue.com/kb/Goto20514.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WF - All Versions &lt;/li&gt;    &lt;li&gt;WFR - All Versions &lt;/li&gt;    &lt;li&gt;SR- All Versions &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What do I need to know when I receive my RMA replacement? &lt;/li&gt;    &lt;li&gt;What do I need to do to set up a RMA replacement device? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;When you receive your replacement device, you will need to take a few additional steps in order for your device to be fully functional. These steps are briefly covered in this article. For more details see the Appliance Install Guide for your product version.&lt;/p&gt;&lt;h3&gt;General Procedure:&lt;/h3&gt;&lt;ol&gt;    &lt;li&gt;Connect to your Appliance with an external monitor and keyboard, or connect via a console cable. You should be able to see output on your screen that shows a login prompt. &lt;/li&gt;    &lt;li&gt;At the login prompt, enter &lt;span style="font-family: 'courier new';"&gt;menu&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;At the password prompt, type the password associated with the menu user. This will be included with the replacement documentation (you can also contact TAC). &lt;/li&gt;    &lt;li&gt;Press 2 to select the Quick start setup process. This will prompt for credentials. You can use the same password as above. &lt;/li&gt;    &lt;li&gt;From the quick start menu, configure the following information.    &lt;ul&gt;        &lt;li&gt;Filtering mode (see Notes below) &lt;/li&gt;        &lt;li&gt;Configure Network Interface LAN 1 &lt;/li&gt;        &lt;li&gt;Configure Network Interface LAN 2 &lt;/li&gt;        &lt;li&gt;Configure Default Gateway &lt;/li&gt;        &lt;li&gt;Configure DNS Servers &lt;/li&gt;        &lt;li&gt;Configure Host name &lt;/li&gt;        &lt;li&gt;Set Time Zone and Regional settings &lt;/li&gt;        &lt;li&gt;(For WFR or SR only) Configure the setup wizard user &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Complete the wizard and follow any additional prompts to finalize your configuration.&lt;/p&gt;&lt;h3&gt;WFR and SR Setup Wizard User:&lt;/h3&gt;&lt;p&gt;The setup wizard user is used exclusively for the SR component. This user must be defined to update to the latest releases. On a WFR, the SR must be configured, as without the SR configuration the WFR will create a backlog of real time logs that cannot be processed.&lt;/p&gt;&lt;p&gt;The wizard user is a temporary account this is used strictly for creating the SR Global admin. The wizard username and password will be changed after you log in and create the SR user.&lt;/p&gt;&lt;p&gt;After you have defined the setup wizard user, log in to the SR or WFR with &lt;span style="font-family: 'courier new';"&gt;https://[ip address of appliance]:8443/&lt;/span&gt; (The port may be different on older appliances, so refer to the Appliance Install Guide or User Guide for your appliance version.)&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;To keep things simple, Trustwave recommends that you replicate your pre-RMA configuration as closely as possible to ensure that you recover to the same state before your RMA request. &lt;/li&gt;    &lt;li&gt;The most common modes of filtering are ‘invisible’ and ‘Bridge Mode’. If you intend to filter via a port mirror, select invisible mode. &lt;/li&gt;    &lt;li&gt;If you are registering a new replacement unit and wish to use the same hostname, contact Trustwave TAC to ensure that there are no duplicates in the registration database. Trustwave can remove the older appliance record from the database to allow you to pick the same hostname. &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Thu, 11 Feb 2016 16:05:20 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Determining why an appliance is not responding to ping</title><link>https://support.levelblue.com/kb/Goto20507.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WF - All Versions &lt;/li&gt;    &lt;li&gt;WFR - All Versions &lt;/li&gt;    &lt;li&gt;SR - All Versions &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Why is my appliance not responding to ping requests? &lt;/li&gt;    &lt;li&gt;Troubleshooting networking before declaring a hardware failure &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;A device not responding to a ping request is often a symptom of a network configuration issue. It could also be caused by a hardware fault. Before starting to process an RMA for hardware fault, it is important to determine whether the security appliance hardware is truly the culprit.&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Log into the appliance with the default setup user credentials. (Contact support for this information.)    &lt;ul&gt;        &lt;li&gt;Press 1 to enter the "display status" and confirm that your network settings are correct. Make a note of the gateway setting because this will be needed for additional testing. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Plug a laptop into the same physical switch as the Appliance and try pinging the IP of the appliance. If you are still not getting a response, try pinging the Gateway.    &lt;ul&gt;        &lt;li&gt;If you get a response when pinging the IP on the same switch, then this is a routing issue. &lt;/li&gt;        &lt;li&gt;If you can still not ping the gateway, then this is a network configuration issue. This will need to be addressed before support can provide additional assistance. If you can ping the gateway, then proceed with Step 3. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Plug a laptop into the same User Interface management port on the switch. This is the interface that is also used when logging into the web browser. On the WF, this is defined in System &amp;gt; Network &amp;gt; LAN Settings. If you are looking at the back of the appliance, the ports are numbered from left to right: LAN1 on the left side, and LAN2 on the right.    &lt;ul&gt;        &lt;li&gt;Try pinging the gateway you noted from Step 1. If you are not getting a response then this points to an issue with the port. Try using a different port and repeat steps 2 and 3. If you do get a response then contact support for additional assistance. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;Networking tips&lt;/h3&gt;&lt;p&gt;Here are some other basic networking tips to help you along the way. &lt;/p&gt;&lt;ul&gt;    &lt;li&gt;Verify that the appliance is in the expected VLAN.  &lt;/li&gt;    &lt;li&gt;Try different network cables.  &lt;/li&gt;    &lt;li&gt;Check the LED indicators on the NICs to determine what type of traffic is being seen over the network. LED colors may have different meaning depending on the NIC manufacturer but here is a general rule of thumb for most modern day NICs.    &lt;ul&gt;        &lt;li&gt;No light - No connection &lt;/li&gt;        &lt;li&gt;Solid Green - Link established &lt;/li&gt;        &lt;li&gt;Flashing Green - Indication that data is being sent/received &lt;/li&gt;        &lt;li&gt;Orange or Red - Errors with NIC or Network &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;Even if you believe nothing has changed on the network, Trustwave cannot process an RMA until these steps have been completed. This is because all devices on a network can be a point of failure. Hardware ages and various components will go bad over time. Basic tests as described will help you to avoid the unnecessary costs and delays from returning a working appliance when the issue was elsewhere in the network.&lt;/p&gt;</description><pubDate>Thu, 11 Feb 2016 14:05:08 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Blocking the Teamviewer Client using the WF or WFR</title><link>https://support.levelblue.com/kb/Goto20502.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WF - All Versions &lt;/li&gt;    &lt;li&gt;WFR - All Versions &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I block Teamviewer software on the web filter? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;Web Filter is a TCP based filter, so it is only able to block TCP packets. The filter can block navigation to the teamviewer.com website since the connection is made over TCP. However, the Teamviewer client also uses UDP. Any UDP based application is out of scope of the filter's design. &lt;/p&gt;&lt;p&gt;To block applications that use UDP traffic you can control application installation via user policies, or block the UDP packets from the application on the firewall. Another option is to combine Web Filter with other Trustwave products which are capable of filtering UDP traffic.&lt;/p&gt;&lt;h3&gt;Diagnosing UDP Ports To Block:&lt;/h3&gt;&lt;p&gt;The procedure below is a suggested starting point to help you determine the ports in use. You may need to experiment to use the procedure in your network environment.&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;Run Wireshark on a workstation that has a connection to teamviewer.  This workstation should be inside your network. &lt;/li&gt;    &lt;li&gt;Have the connecting host from outside of the network provide their IP address (they can determine this by navigating to whatismyip.com). You can use the IP address as a filter in Wireshark to see only the traffic to this IP using the following filter: &lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;    ip.addr==[external address] &amp;amp;&amp;amp; udp&lt;br /&gt;    &lt;/span&gt;&lt;br /&gt;    For example:&lt;br /&gt;    &lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt;     ip.addr==203.0.113.1 &amp;amp;&amp;amp; udp&lt;br /&gt;    &lt;/span&gt; &lt;/li&gt;    &lt;li&gt;If the connection is local, use the internal IP to filter. &lt;/li&gt;    &lt;li&gt;You should be able to deduce from the output which packets are generated by Teamviewer. On the packet details pane you will see an entry similar to:&lt;br /&gt;    &lt;span style="font-family: 'courier new';"&gt; &lt;br /&gt;    User Datagram Protocol, Src Port: mapper-ws-ethd (3986), Dst Port:56869 (56869)&lt;br /&gt;    &lt;/span&gt;  &lt;/li&gt;    &lt;li&gt;Blocking the non-ephemeral port at the firewall should stop the teamviewer traffic. However, if teamviewer changes the UDP port, you will need to run the same test and continue this process until no connections are established.   &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;You can use this same procedure to try stopping connections from other UDP based applications.&lt;/p&gt;</description><pubDate>Wed, 03 Feb 2016 18:03:41 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Blocking web traffic over QUIC (Quick UDP Internet Connections) protocol </title><link>https://support.levelblue.com/kb/Goto20269.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter - all versions &lt;/li&gt;    &lt;li&gt;WFR - all versions &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Can the Web Filter block connections over the QUIC (Quick UDP Internet Connections) protocol developed by Google? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter is not able to block connections over the QUIC protocol.  QUIC uses UDP over ports 80 and 443. The Web Filter does not block UDP traffic.   &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Recommended Actions:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;The recommended fix is to block outbound UDP on ports 80 and 443 at the firewall/UTM level. &lt;/li&gt;    &lt;li&gt;It is possible to disable QUIC in Chrome. Navigate to chrome://flags and disable the setting for "Experimental QUIC protocol".  &lt;/li&gt;    &lt;li&gt;As of Chrome version 43, the ability to disable QUIC has been added to Windows Group Policy (GPO) templates (&lt;span style="font-family: 'courier new';"&gt;Software\Policies\Chromium\QuicAllowed&lt;/span&gt;).  You can see a full set of supported policies at: &lt;a href="http://www.chromium.org/administrators/policy-list-3" class="ApplyClass" target="_blank"&gt;http://www.chromium.org/administrators/policy-list-3&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Tue, 19 Jan 2016 17:29:25 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Correcting a Certificate Revoked issue for the web interface</title><link>https://support.levelblue.com/kb/Goto20483.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter - All Versions &lt;/li&gt;    &lt;li&gt;WFR - All Versions &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How can I access the web interface if the TLS/SSL Certificate for the site is revoked? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;h3&gt;Part 1:&lt;/h3&gt;&lt;ol&gt;    &lt;li&gt;Open the Java Control Panel and select the Advanced tab. &lt;/li&gt;    &lt;li&gt;Locate the options for Certificate Revocation checks. Temporarily change the settings. Note that different versions of Java have different wording. The wording below is correct at version 8, update 66.    &lt;ul&gt;        &lt;li&gt;Set &lt;em&gt;Perform signed code certificate revocation checks on&lt;/em&gt; to "Do not check (not recommended)" &lt;/li&gt;        &lt;li&gt;Set &lt;em&gt;Perform TLS certificate revocation checks on&lt;/em&gt; to "Do not check (not recommended)" &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;strong&gt;Remember to go back to the recommended setting&lt;/strong&gt; "All certificates in the chain of trust" after you have generated your new certificate.&lt;br /&gt;&lt;br /&gt;At this stage, you should have access to the product web interface.&lt;/p&gt;&lt;h3&gt;Part 2:&lt;/h3&gt;&lt;p&gt;From the User Interface:&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Navigate to System &amp;gt; Authentication &amp;gt; Enable/Disable. Make sure this option is enabled.    &lt;ul&gt;        &lt;li&gt;If the option was not enabled, enabling it will take 2-3 minutes as some of the Tomcat services will be restarted. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Once the setting is enabled, select Authentication &amp;gt; Authentication SSL certificate &amp;gt; Download/View Certificate    &lt;ul&gt;        &lt;li&gt;Confirm that the certificate is invalid. Invalidity is most often caused by hostname mismatches, or an expired SSL certificate. If either applies to you, then you will want to delete the certificate via this tab. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Create a new self-signed certificate: Authentication &amp;gt; Authentication SSL certificate &amp;gt; Self Signed Certificate &amp;gt; Create Self Signed Certificate. &lt;/li&gt;&lt;/ol&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;During the above changes, services are being restarted to load the configuration. If you see an error message,  a service may still be in the process of being restarted. Wait a short time and try again.&lt;/p&gt;&lt;h3&gt;Part 3:&lt;/h3&gt;&lt;p&gt;After the certificate has been created:&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Test by setting authentication back to disable ( Authentication &amp;gt; Authentication Enable/Disable &amp;gt; Set to disable (only applies if system is used for authentication). &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Remember to change the two Java certificate revocation check settings to the recommended setting&lt;/strong&gt; "All certificates in the chain of trust" &lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;Additional information can be found in article &lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle12600.aspx" target="_blank"&gt;Q12600&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Tue, 19 Jan 2016 14:27:14 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Secure Connection Failed when connecting to SR or WF web UI using Firefox 39</title><link>https://support.levelblue.com/kb/Goto20353.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WFR 5.1.30 and older &lt;/li&gt;    &lt;li&gt;WF 5.1.30 and older &lt;/li&gt;    &lt;li&gt;SR 5.1.30 and older &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Mozilla Firefox 39 and later versions will not connect to the web GUI of WF or SR &lt;/li&gt;    &lt;li&gt;After upgrading to the newest version of Firefox, you are unable to connect to the GUI &lt;/li&gt;    &lt;li&gt;Error message: &lt;span style="font-family: 'courier new';"&gt;SSL received a weak ephemeral Diffie-Hellman key in Server Key Exchange handshake message.&lt;br /&gt;    &lt;/span&gt; &lt;br /&gt;    &lt;img alt="" style="font-size: 8pt; height: 356px; width: 500px; line-height: 11px;" src="https://support.levelblue.com/kb/Uploads/Images/Lcreager/Weak%20DHE/2015-07-20%2009_22_55-XenCenter.jpg" /&gt; &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h2&gt;Cause:&lt;/h2&gt;&lt;p&gt;This issue is caused by a combination of SSL cipher configuration on the device and enhanced security requirements in new versions of Firefox.&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;This problem will be resolved in a future patch to the WF and SR appliance software. &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Workaround:&lt;/h3&gt;&lt;p&gt;To temporarily fix the issue in Firefox, you can manually disable the ciphers using the following steps:&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Open Firefox. In the address bar enter &lt;span style="font-family: 'courier new';"&gt;about:config&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;Click the button &lt;strong&gt;I'll be careful, I promise!&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;In the search box, enter &lt;span style="font-family: 'courier new';"&gt;ssl3&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;Double click on these two ciphers listings to disable use (they are normally the top two listed)    &lt;ul&gt;        &lt;li&gt;security.ssl3.dhe_rsa_aes_128_sha &lt;/li&gt;        &lt;li&gt;security.ssl3.dhe_rsa_aes_256_sha &lt;/li&gt;    &lt;/ul&gt;    The disabled items should display in boldface with a value of &lt;strong&gt;false&lt;/strong&gt;, as shown below:&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" style="height: 365px; width: 563px;" src="https://support.levelblue.com/kb/Uploads/Images/20353/ciphersdisabled.png" /&gt; &lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Note: &lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;It is also possible to disable the ciphers on the appliance, which resolves the issue for all users. Contact Support for assistance. To disable the ciphers, Support will require remote (ssh) access to the device experiencing the issue. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Mon, 20 Jul 2015 18:05:27 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Database Category listing</title><link>https://support.levelblue.com/kb/Goto20349.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WF - All Versions &lt;/li&gt;    &lt;li&gt;WFR - All Versions &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What is the current category listing? &lt;/li&gt;    &lt;li&gt;What are the short names and full names of categories? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;The easy way to determine the short name for a category is to left click on the category and select library details. This will display the long name and short name relationship. &lt;/p&gt;&lt;p&gt;The listing in this article shows the default categories as of the date when the article was updated. To learn more about the purpose of each category, see the &lt;a href="https://www.trustwave.com/Resources/Library/Documents/Trustwave-Web-Filtering-Content-Categories/" class="ApplyClass" target="_blank"&gt;Content Categories Spec Sheet&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;Adult Content:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Child Pornography - KDPORN &lt;/li&gt;    &lt;li&gt;Explicit Art - EXART &lt;/li&gt;    &lt;li&gt;Obscene/Tasteless - OBSC &lt;/li&gt;    &lt;li&gt;Pornography/Adult Content - GPORN &lt;/li&gt;    &lt;li&gt;R Rated - RRATED &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Bandwidth:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Image Servers &amp;amp; Image Search Engines - IMAGES &lt;/li&gt;    &lt;li&gt;Internet Radio - IRADIO &lt;/li&gt;    &lt;li&gt;March Madness Streaming - MMDSTRM &lt;/li&gt;    &lt;li&gt;Olympic Streaming - OLMSTRM &lt;/li&gt;    &lt;li&gt;Peer-to-peer/File Sharing - PR2PR &lt;/li&gt;    &lt;li&gt;Video Sharing - VIDSHAR &lt;/li&gt;    &lt;li&gt;VoIP - VOIP &lt;/li&gt;    &lt;li&gt;Web Based Storage - WSTORE &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Streaming Media:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Flash Video - FLV &lt;/li&gt;    &lt;li&gt;Generic Streaming Media - GSTREAM &lt;/li&gt;    &lt;li&gt;QuickTime Video - QTV &lt;/li&gt;    &lt;li&gt;Real Time Streaming Protocol - RTSP &lt;/li&gt;    &lt;li&gt;Windows Media Video - WMV &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Business/Investments:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Employment - EMPL &lt;/li&gt;    &lt;li&gt;Financial Institution - FINAN &lt;/li&gt;    &lt;li&gt;General Business - GENBUS &lt;/li&gt;    &lt;li&gt;Online Trading/Brokerage - TRADING &lt;/li&gt;    &lt;li&gt;Real Estate - ESTATE &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Community/Organizations: &lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Community/Organizations - COMORG &lt;/li&gt;    &lt;li&gt;Local Community - LCOMM &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Education:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Education - EDUCAT &lt;/li&gt;    &lt;li&gt;Educational Games - EDUGAM &lt;/li&gt;    &lt;li&gt;Online Classes - ONLCLS &lt;/li&gt;    &lt;li&gt;Reference - REFERE &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Entertainment:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Art - ART &lt;/li&gt;    &lt;li&gt;Comics - COMICS &lt;/li&gt;    &lt;li&gt;Entertainment - GENTER &lt;/li&gt;    &lt;li&gt;Gambling - GAMB &lt;/li&gt;    &lt;li&gt;Humor - HUMOR &lt;/li&gt;    &lt;li&gt;Kids - GKIDS &lt;/li&gt;    &lt;li&gt;Movies &amp;amp; Television - MOVTEL &lt;/li&gt;    &lt;li&gt;Music Appreciation - MUSAPP &lt;/li&gt;    &lt;li&gt;Online Greeting Cards - GRTCRD &lt;/li&gt;    &lt;li&gt;Restaurant/Dining - RESTAUR &lt;/li&gt;    &lt;li&gt;Theater - THEATR &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Games:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Games - GGAMES &lt;/li&gt;    &lt;li&gt;Games Patterns - GAMPTRN &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Government/Law/Politics:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Government - GOVT &lt;/li&gt;    &lt;li&gt;Legal - LEGAL &lt;/li&gt;    &lt;li&gt;Military Appreciation - MILAPP &lt;/li&gt;    &lt;li&gt;Military Official - MILOFL &lt;/li&gt;    &lt;li&gt;Political Opinion - POLTIC &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Health/Fitness:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Fitness - FITNS &lt;/li&gt;    &lt;li&gt;Health/Medical - HEALTH &lt;/li&gt;    &lt;li&gt;Holistic - HOLSTC &lt;/li&gt;    &lt;li&gt;Self Help - GSELF &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Illegal/Questionable:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Criminal Skills - GCRIMI &lt;/li&gt;    &lt;li&gt;Dubious/Unsavory - DUBIUS &lt;/li&gt;    &lt;li&gt;Hate &amp;amp; Discrimination - HATE &lt;/li&gt;    &lt;li&gt;Illegal Drugs - DRUGS &lt;/li&gt;    &lt;li&gt;School Cheating - EDUCHT &lt;/li&gt;    &lt;li&gt;Terrorist/Militant/Extremist - TERROR &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Information Technology:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Dynamic DNS Services - DYNDNS &lt;/li&gt;    &lt;li&gt;Freeware/Shareware - FREEWAR &lt;/li&gt;    &lt;li&gt;Information Technology - INTECH &lt;/li&gt;    &lt;li&gt;Internet Service Provider - ISP &lt;/li&gt;    &lt;li&gt;Portals - PORTALS &lt;/li&gt;    &lt;li&gt;Search Engines - SE &lt;/li&gt;    &lt;li&gt;Web Based Newsgroups - WNEWS &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Internet Communication:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Chat - CHAT &lt;/li&gt;    &lt;li&gt;Message Boards - MESBRD &lt;/li&gt;    &lt;li&gt;Online Communities - ONLCOM  &lt;/li&gt;    &lt;li&gt;Translation Services - TRANSRV &lt;/li&gt;    &lt;li&gt;Web Based Email - WEMAIL &lt;/li&gt;    &lt;li&gt;Web Logs/Personal Pages - WEBLOG &lt;/li&gt;    &lt;li&gt;Web-Based Productivity Apps - WEBPROD &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Instant Messaging (IM):&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt; Generic IM - IMGEN &lt;/li&gt;    &lt;li&gt; Google Chat - IMGCHAT &lt;/li&gt;    &lt;li&gt; Google Talk - IMGTALK &lt;/li&gt;    &lt;li&gt; ICQ &amp;amp; AIM - ICQAIM &lt;/li&gt;    &lt;li&gt; IRC - IMIRC &lt;/li&gt;    &lt;li&gt; Meebo - IMMEEBO &lt;/li&gt;    &lt;li&gt; My Space IM - IMMYSP &lt;/li&gt;    &lt;li&gt; PoPo - IMPOPO &lt;/li&gt;    &lt;li&gt; QQ - IMQQ &lt;/li&gt;    &lt;li&gt; ToToMoMo - IMTOMO &lt;/li&gt;    &lt;li&gt; WangWang - IMWWNG &lt;/li&gt;    &lt;li&gt; Windows Live Messenger - IMMSN &lt;/li&gt;    &lt;li&gt; Yahoo IM - IMYAHOO &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Internet Productivity:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Adware - ADWARE &lt;/li&gt;    &lt;li&gt;Banner/Web Ads - BANNER &lt;/li&gt;    &lt;li&gt;Fantasy Sports - FANSPRT &lt;/li&gt;    &lt;li&gt;Free Hosts - FREEHST &lt;/li&gt;    &lt;li&gt;Web Hosts - WEB_HST &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Remote Access:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Generic Remote Access - REM_ACC &lt;/li&gt;    &lt;li&gt;GoToMyPC - GO2MYPC &lt;/li&gt;    &lt;li&gt;Remote Desktop - RMTDESK &lt;/li&gt;    &lt;li&gt;Secure Shell - SSH &lt;/li&gt;    &lt;li&gt;Virtual Network Computing - VNC &lt;/li&gt;    &lt;li&gt;pcAnywhere - PCANYWH &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Internet/Intranet Misc:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Domain Landing - DOMAINL &lt;/li&gt;    &lt;li&gt;Edge Content Servers/Infrastructure - EDGECON &lt;/li&gt;    &lt;li&gt;Invalid Web Pages - INVD_PG &lt;/li&gt;    &lt;li&gt;Reviewed/Miscellaneous - RE_MISC &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;News/Reports:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;March Madness News - MMDNEWS &lt;/li&gt;    &lt;li&gt;News - GNEWS &lt;/li&gt;    &lt;li&gt;Olympic News - OLMNEWS &lt;/li&gt;    &lt;li&gt;Sports - SPORTS &lt;/li&gt;    &lt;li&gt;Weather/Traffic - TRAFIC &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Religion/Beliefs:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Paranormal - PARNML &lt;/li&gt;    &lt;li&gt;Religion - RELIG &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Security: &lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Bad Reputation Domains - BADREP &lt;/li&gt;    &lt;li&gt;BotNet - BOTNET &lt;/li&gt;    &lt;li&gt;Hacking - HACK &lt;/li&gt;    &lt;li&gt;Malicious Code/Virus - MALCOD &lt;/li&gt;    &lt;li&gt;Phishing - PHISHIN &lt;/li&gt;    &lt;li&gt;Spyware - SPYWARE &lt;/li&gt;    &lt;li&gt;Web-based Proxies/Anonymizers - PROXY &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Shopping:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Online Auction - AUCTION &lt;/li&gt;    &lt;li&gt;Shopping - SHOP &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Society/Lifestyles:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Alcohol - ALCO &lt;/li&gt;    &lt;li&gt;Animals/Pets - ANIMALS &lt;/li&gt;    &lt;li&gt;Books &amp;amp; Literature/Writings - BNL &lt;/li&gt;    &lt;li&gt;Dating/Personals - DATE &lt;/li&gt;    &lt;li&gt;Fashion - FASHN &lt;/li&gt;    &lt;li&gt;Lifestyle &amp;amp; Culture - LIFE &lt;/li&gt;    &lt;li&gt;Recreation - RECREA &lt;/li&gt;    &lt;li&gt;Self Defense - SELFDE &lt;/li&gt;    &lt;li&gt;Social Opinion - SOCOPN &lt;/li&gt;    &lt;li&gt;Tobacco - TOBACCO &lt;/li&gt;    &lt;li&gt;Weapons - WEAPN &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Travel/Events:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Tickets - TICKET &lt;/li&gt;    &lt;li&gt;Travel - TRAVEL &lt;/li&gt;    &lt;li&gt;Vehicles - AUTO &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;This listing is subject to change at any time (although the core categories are very unlikely to change). If you notice that a short name does not match, ensure your installation has the latest library updates. &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Thu, 16 Jul 2015 18:45:29 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Allowing or Blocking YouTube Access</title><link>https://support.levelblue.com/kb/Goto20336.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter (R3000), including WFR &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How can I allow or block YouTube access for specific users? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Comments:&lt;/h2&gt;&lt;p&gt;IP addresses should not be added to custom URL categories with YouTube sites. This is because YouTube shares the same certificate across multiple services. IP addresses listed in a custom URL category for Google or YouTube sites must be removed or inconsistent filtering results will occur. &lt;/p&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;Follow these steps to address issues with YouTube access:&lt;/p&gt;&lt;h3&gt;Add a Custom Category for access&lt;/h3&gt;&lt;ol&gt;    &lt;li&gt;From the main Web Filter window select &lt;strong&gt;Library &amp;gt; Category Groups &amp;gt; Custom Categories.&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Select the group that you have created for YouTube. &lt;/li&gt;    &lt;li&gt;Choose &lt;strong&gt;URLs.&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;In  the &lt;strong&gt;Edit Wildcard URL List&lt;/strong&gt; pane, type &lt;span style="font-family: 'courier new';"&gt;*.googlevideo.com&lt;/span&gt; and then click &lt;strong&gt;Add.&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;Ensure &lt;span style="font-family: 'courier new';"&gt;*googlevideo.com&lt;/span&gt; is highlighted, click &lt;strong&gt;Apply&lt;/strong&gt;, and then click &lt;strong&gt;Reload Library&lt;/strong&gt;. &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;You may also want to checking whether the following domains are also listed in the custom category:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;*.googlevideo.com &lt;/li&gt;    &lt;li&gt;*.ytimg.com &lt;/li&gt;    &lt;li&gt;*.youtube-nocookie.com &lt;/li&gt;    &lt;li&gt;*.youtube.com &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Reloading the library could take up to 10 minutes. &lt;/p&gt;&lt;h3&gt;Allow Profile access&lt;/h3&gt;&lt;p&gt;If you are still unable to view YouTube videos, check the following:&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;In the main Web Filter window, navigate to &lt;strong&gt;Policy &amp;gt; IP&lt;/strong&gt; or &lt;strong&gt;Policy &amp;gt; LDAP&lt;/strong&gt; (depending on the type of policy in use). &lt;/li&gt;    &lt;li&gt;Select a group that you want to allow to play YouTube Videos. &lt;/li&gt;    &lt;li&gt;Navigate to &lt;strong&gt;Group Profile &amp;gt; Custom Categories&lt;/strong&gt; (or &lt;strong&gt;Profile &amp;gt; Custom Categories&lt;/strong&gt; when LDAP is in use). &lt;/li&gt;    &lt;li&gt;Select the group that you have created for YouTube, set it to ALLOW, and then click &lt;strong&gt;Apply&lt;/strong&gt;. &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Repeat the above steps for each group that is allowed to play YouTube videos. &lt;/p&gt;&lt;h3&gt;Check Custom Categories&lt;/h3&gt;&lt;p&gt;If users are still unable to view YouTube after the above steps are completed, it is highly likely that IP addresses are listed in a custom category. &lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Perform a library lookup on googlevideo.com, ytimg.com, youtube-nocookie.com, youtube.com and google.com. &lt;/li&gt;    &lt;li&gt;Remove any IP addresses that have been added to a custom category and then retest. &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;If you are still having issues or see an excessive number of individual IPs listed, contact Trustwave for additional assistance. See contact details at the end of this article.&lt;/p&gt;</description><pubDate>Mon, 06 Jul 2015 18:01:23 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>User not filtered properly</title><link>https://support.levelblue.com/kb/Goto19481.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Requests from a user are not being filtered as expected. What are the steps to troubleshoot this situation? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;Run an active profile lookup on the IP that is not being filtered properly and note what Group they are currently being filtered under.&lt;/p&gt;&lt;h3&gt;Groups:&lt;/h3&gt;&lt;p&gt;Is the user in the expected group?&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;If the user EXISTS in the expected group:    &lt;ul&gt;        &lt;li&gt;On the ruleset in the active profile lookup, confirm that the site in question is set to the appropriate level:        &lt;ul&gt;            &lt;li&gt;&lt;strong&gt;Block:&lt;/strong&gt; Site will be blocked unless an allow exists which will take precedence. &lt;/li&gt;            &lt;li&gt;&lt;strong&gt;Allow:&lt;/strong&gt; Should always take precedence. &lt;/li&gt;            &lt;li&gt;&lt;strong&gt;Pass:&lt;/strong&gt; Does nothing other than allows the traffic to pass. If the site is in multiple categories and one is set to block, the site would then be blocked. &lt;/li&gt;        &lt;/ul&gt;        &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;If the user IS NOT in the expected group: &lt;/li&gt;&lt;/ol&gt;&lt;h3&gt;LDAP:&lt;/h3&gt;&lt;ol start="3"&gt;    &lt;li&gt;Is the user being filtered via LDAP?    &lt;ul&gt;        &lt;li&gt;If so, confirm that the system in question has the authenticat program running. &lt;/li&gt;        &lt;li&gt;You can check by looking in the windows Task Manager and searching for an instance of Authenticat. &lt;/li&gt;        &lt;li&gt;You can also check (if installed via a service) if the program is running as a service.        &lt;ul&gt;            &lt;li&gt;Run services.msc (windows key + R) and search for the M86 Authenticator service &lt;/li&gt;        &lt;/ul&gt;        &lt;/li&gt;        &lt;li&gt;Are multiple instances of the M86 authenticator running? Multiple instances can cause inconsistent filtering results, because all instances will attempt to bind to the same port, but only one instance can bind at a time.        &lt;ul&gt;            &lt;li&gt;Multiple instances can be caused by GPO or batch files. &lt;/li&gt;        &lt;/ul&gt;        &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Is the Domain marked as inactive?    &lt;ul&gt;        &lt;li&gt;If the domain was recently rebooted, you may need to re-activate the domain. &lt;/li&gt;        &lt;li&gt;If you experience errors when attempting to activate the domain, contact Trustwave TAC. &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ol&gt;</description><pubDate>Thu, 02 Jul 2015 11:42:56 GMT</pubDate><dc:creator>Brian Abildgaard</dc:creator></item><item><title>Enforcing Google Safe Search Over SSL When Using Invisible Mode</title><link>https://support.levelblue.com/kb/Goto20211.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;R3000 &lt;/li&gt;    &lt;li&gt;Web Filter (WF, WFR) &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li style="box-sizing: border-box;"&gt;Can Web Filter enforce safe-search for SSL-based Google search and Youtube in invisible mode? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;No, the filter cannot enforce safe-search for Google search or YouTube in invisible mode.  You can read more about why in article &lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle13898.aspx" class="ApplyClass" target="_blank"&gt;Q13898&lt;/a&gt;.  &lt;/p&gt;&lt;h3&gt;Workaround&lt;/h3&gt;&lt;p&gt;There is a DNS workaround that can be put into place.  You can read the official answer from &lt;a href="https://support.google.com/websearch/answer/186669?hl=en" class="ApplyClass" target="_blank"&gt;Google here&lt;/a&gt; under option 3.&lt;/p&gt;&lt;p&gt;To enforce safe search, update the DNS configuration for your network. Set the DNS entries for &lt;span style="font-family: 'courier new';"&gt;www.google.com&lt;/span&gt; and any other Google ccTLD subdomains to a CNAME entry for &lt;span style="font-family: 'courier new';"&gt;forcesafesearch.google.com&lt;/span&gt;  This will enforce encrypted safe-search on your entire network for any Google searches.&lt;/p&gt;&lt;p&gt;A similar process can be followed to enforce Safety Mode for videos on YouTube.  To enforce Safety Mode on Youtube set the DNS entries for &lt;span style="font-family: 'courier new';"&gt;www.youtube.com&lt;/span&gt; and any other Google ccTLD subdomains to a CNAME entry for &lt;span style="font-family: 'courier new';"&gt;forcesafesearch.google.com&lt;/span&gt;.  This will enforce Safety Mode for YouTube videos.  &lt;/p&gt;</description><pubDate>Thu, 07 May 2015 18:23:31 GMT</pubDate><dc:creator>Andrew Davies</dc:creator></item><item><title>Add multiple users to the Certificate management using a text file </title><link>https://support.levelblue.com/kb/Goto15217.aspx</link><description>&lt;h2&gt;&lt;span style="font-family: verdana;"&gt;This article applies to:           &lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;&lt;strong&gt;WFR 5.0.20   &lt;/strong&gt;(Synced as a Source to a Web Filter in Mobile Mode)&lt;/span&gt; &lt;/li&gt;    &lt;span style="font-family: verdana; font-size: 13px;"&gt;    &lt;/span&gt;    &lt;li&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;&lt;strong&gt;WF 5.0.20     &lt;/strong&gt;(Configured in Mobile Mode)&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;h2&gt;&lt;span style="font-family: verdana;"&gt;Question:&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;&lt;strong&gt;How can I add multiple users to the Certificate management under IP group profiles?&lt;/strong&gt;&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;h2&gt;&lt;span style="font-family: verdana;"&gt;Information:&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p&gt;&lt;span style="font-family: verdana;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;You can use the format listed below to add multiple users to the Certificate management &lt;/span&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;using a text file&lt;/span&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;:&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana;"&gt;&lt;strong&gt;&lt;span style="font-size: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana;"&gt;&lt;strong&gt;&lt;span style="font-size: 13px;"&gt;Name,Email,Profile,Privatekey password&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;&lt;strong&gt;Example :&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;John Doe,johndoe@xyz.com,MobileUser,johndoe_xyz&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana; font-size: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;div style="width: 700px; overflow: auto;"&gt;&lt;span style="font-family: verdana;"&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/Saad/adding%20users.jpg" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-size: 13px;"&gt;Log in to the Filter and go to &lt;strong&gt;Profile&lt;/strong&gt; &amp;gt;&lt;strong&gt;IP&lt;/strong&gt; &amp;gt;&lt;strong&gt;MobileUser&lt;/strong&gt; &amp;gt;&lt;strong&gt;Certificate Management &lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-size: 13px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;Use the Import Users options on the bottom of this window to import your text file. &lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p&gt;&lt;span style="font-family: verdana;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;h2&gt;&lt;span style="font-family: verdana;"&gt;Notes:&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;&lt;em&gt;*The private key password needs to be at least 8 characters long while containing numbers and special characters.&lt;/em&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana; font-size: 13px;"&gt;&lt;em&gt;*MobileUser is the name given to the IP profile to distinguish Mobile users for this article. Certificates can be added to any IP Profile . &lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p&gt;&lt;span style="font-family: verdana;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;p&gt;&lt;span style="font-family: verdana;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;</description><pubDate>Thu, 08 Jan 2015 11:37:52 GMT</pubDate><dc:creator>William Martino</dc:creator></item><item><title>Inline Filtering and Google Services</title><link>https://support.levelblue.com/kb/Goto19657.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter and WFR versions 5.1.00 and above &lt;/li&gt;    &lt;li&gt;Inline filtering configured (available in Bridge, Router, or Firewall mode) &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Some Google services do not work when inline filtering is configured. &lt;/li&gt;    &lt;li&gt;Affected services can include Chromebook login, Gmail, and Google Drive. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;Google secure (HTTPS) sites are configured in a way that does not work with inline HTTPS inspection as performed by the Web Filter.&lt;/p&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;To resolve this issue it is necessary to deploy a PAC file (Proxy Auto-Configuration) that directs traffic appropriately.&lt;/p&gt;&lt;p&gt;Deployment of this solution requires system access to the Web Filter software. &lt;/p&gt;&lt;p&gt;To arrange for this deployment please contact Trustwave Support. &lt;/p&gt;</description><pubDate>Thu, 11 Sep 2014 15:50:09 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>How to block, or un-block, a site</title><link>https://support.levelblue.com/kb/Goto12355.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter&lt;/li&gt;    &lt;li&gt;WFR&lt;/li&gt;    &lt;li&gt;R3000 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;p&gt;How to block, or un-block, a site &lt;/p&gt;&lt;h2&gt;Reply&lt;/h2&gt;&lt;p&gt;If you want us to review a URL to determine if we categorized it correctly, please send it to &lt;span style="font-family: courier new;"&gt;wfrsupport@trustwave.com&lt;/span&gt;. &lt;/p&gt;&lt;p&gt;We also encourage you to submit URLs that are not currently categorized in our library database. &lt;/p&gt;&lt;p&gt;To block a web site on the R3000 Internet filter: &lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Perform a Library Lookup:    &lt;ol&gt;        &lt;li&gt;From the filter GUI, click on the “Library” button at the top of the screen. &lt;/li&gt;        &lt;li&gt;Click on “Library Lookup” in the left-side menu &lt;/li&gt;        &lt;li&gt;Type the complete URL (including the http:// header) into the URL field &lt;/li&gt;        &lt;li&gt;Click Lookup. If the URL in question in already in a category, you can either block that specific category or place the URL into a custom created category. &lt;/li&gt;    &lt;/ol&gt;    &lt;/li&gt;    &lt;li&gt;To add a URL to an existing category:    &lt;ol&gt;        &lt;li&gt;Click on the “Library” button at the top of the screen. &lt;/li&gt;        &lt;li&gt;Click on the “+” symbol next to the “8e6 Supplied Categories” link on the left side of the screen. This will expand the list of our categories. &lt;/li&gt;        &lt;li&gt;Click on the specific category. &lt;/li&gt;        &lt;li&gt;Click on “URL” &lt;/li&gt;        &lt;li&gt;Type the URL into the URL field. Be sure to include the proper header information (http://). &lt;/li&gt;        &lt;li&gt;Click on “Add” &lt;/li&gt;    &lt;/ol&gt;    &lt;/li&gt;    &lt;li&gt;To add a URL to a custom category:    &lt;ol&gt;        &lt;li&gt;Click on the “Library” button at the top of the screen. &lt;/li&gt;        &lt;li&gt;Click on “Custom Category” &lt;/li&gt;        &lt;li&gt;Click on “Add Category” &lt;/li&gt;        &lt;li&gt;Type in the description and short name of your category and click “Apply”. &lt;/li&gt;        &lt;li&gt;Click on “Custom Category” &lt;/li&gt;        &lt;li&gt;Click on “Refresh” &lt;/li&gt;        &lt;li&gt;Click on your newly added category &lt;/li&gt;        &lt;li&gt;Click on “URLs” &lt;/li&gt;        &lt;li&gt;Type the URL into the URL field. Be sure to include the proper header information (http://) &lt;/li&gt;        &lt;li&gt;Click on “Add” &lt;/li&gt;    &lt;/ol&gt;    &lt;/li&gt;    &lt;li&gt;Reload the Library:    &lt;ol&gt;        &lt;li&gt;Click on the “Library” button at the top of the screen. &lt;/li&gt;        &lt;li&gt;Click on “Library Update” on the left side of the screen. &lt;/li&gt;        &lt;li&gt;Click on “Reload Library” at the bottom right side of the screen &lt;/li&gt;    &lt;/ol&gt;    &lt;/li&gt;    &lt;li&gt;Modify your Group settings to block the new category    &lt;ol&gt;        &lt;li&gt;Click on the “Group” button at the top of the screen &lt;/li&gt;        &lt;li&gt;Click on either Global Group or the specific group that you wish to modify &lt;/li&gt;        &lt;li&gt;For global group – click on Rules and choose which categories should be blocked. Include the new category that you just created or just added the site to and this site will now be blocked. Some web sites are particularly difficult to block because they utilize many—and sometimes obscure—URLs For example: www.myspace.com browseusers.myspace.com a.myspace.com j.myspace.com &lt;br /&gt;        &lt;br /&gt;        You can effectively block all permutations of "myspace.com" using wildcards. First, create a custom category. Then add the wildcard version of the URL (e.g. "*.myspace.com") to your custom category. Go to your Global Group Profile and/or IP Group Profile and move your custom category to the "Blocked" list. Be sure to "Apply" your changes and "Reload Library." &lt;/li&gt;    &lt;/ol&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;To un-block a web site on the Internet filter: &lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Perform a Library Lookup:    &lt;ol&gt;        &lt;li&gt;From the GUI, click on the “Library” button at the top of the screen. &lt;/li&gt;        &lt;li&gt;Click on “Library Lookup” in the left-side menu &lt;/li&gt;        &lt;li&gt;Type the complete URL (including the http:// header) into the URL field &lt;/li&gt;        &lt;li&gt;You will see of categories in which the URL is a member of &lt;/li&gt;    &lt;/ol&gt;    &lt;/li&gt;    &lt;li&gt;Removing the URL from the library:    &lt;ol&gt;        &lt;li&gt;Simply click on the URL line item in the search return window and click on the Remove button &lt;/li&gt;        &lt;li&gt;Click on Reload Library Please do not hesitate to contact our technical support staff for further assistance on this matter. &lt;/li&gt;    &lt;/ol&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;dl style="margin-top: 10px;"&gt;    &lt;dt&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt; &lt;/dt&gt;    &lt;dd&gt;&lt;em&gt;8e6 KB 276537&lt;/em&gt; &lt;/dd&gt;&lt;/dl&gt;</description><pubDate>Sun, 07 Sep 2014 15:24:58 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>URL is not categorized correctly</title><link>https://support.levelblue.com/kb/Goto13685.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Enterprise Filter  &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;URL is not categorized correctly &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;Trustwave strives to keep accurate site categorizations.  Since everyone has differing Internet access standards, occasionally you may find a site you feel should be categorized differently than it is. To submit a Web site that you would like us to review, you can use the &lt;a href="https://support.levelblue.com/submit-a-site.asp" class="ApplyClass" target="_blank"&gt;Submit a site&lt;/a&gt; form.&lt;/p&gt;&lt;p&gt;You are also welcome to send your library queries directly to our library department by writing to &lt;a href="mailto:wfrsupport@Trustwave.com"&gt;wfrsupport@Trustwave.com&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;If you have emailed us with a link to a site you feel should be blocked, our Site Review Team will process the request, usually within one business day. If the site is found to meet the definition for addition to one of our categories as described in the &lt;a href="https://www3.trustwave.com/web-security/web-filtering/database-categories/" target="_blank"&gt;category listing&lt;/a&gt;, then the site will be categorized and included in the daily updates within three business days-and very often the next day.&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;If you are not the filter administrator and you are being blocked from a site you feel you should have access to, please contact your system administrator or ISP, which ever is appropriate. They have the ability to permit you access to any blocked site. We do not administer the filter. If you are the filter administrator and like to re-categorize it locally, please contact Trustwave Technical Support team for further assistance.&lt;/p&gt;</description><pubDate>Sun, 07 Sep 2014 15:24:03 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>Youtube video setup</title><link>https://support.levelblue.com/kb/Goto16513.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter 5.1.05.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I get Youtube videos to work with a video playback error?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;The following URLs need to be allowed either in a Custom Category or Exception URL for the user:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;*.youtube.com&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;*.ytimg.com&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;*.youtube-nocookie.com&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;As of November 25th, 2013:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;*.googlevideo.com&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;Instructions:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;1) Log in to the Web Filter&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;2) go to Library &amp;gt; Custom Category&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;3) Click on the custom category you have for Youtube or Allow and then &amp;gt; URL&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;4)  Add the URL's listed above to the list as wildcards, hit apply action after every add then reload library when they are all done.  (Library Reload will take 5+ minutes)&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;5) Go to Policy &amp;gt; User group &amp;gt; Profile &amp;gt; Custom Category and make sure that the appropriate category is set to Allow.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;6) Repeat these steps for every user group you wish to have Youtube access.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;If you have further questions, do not hesitate to contact WFR Support.&lt;/span&gt;&lt;/p&gt;</description><pubDate>Thu, 05 Dec 2013 12:07:25 GMT</pubDate><dc:creator>Angel Berrios</dc:creator></item><item><title>Where can I find Hardware/Power Specifications for the WF and WFR Series?</title><link>https://support.levelblue.com/kb/Goto13817.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Web Filter (WF) appliances&lt;/li&gt;    &lt;li&gt;Web Filtering and Reporting Suite (WFR) appliances&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Where can I find Hardware/Power Specifications for the WF Series?&lt;/li&gt;    &lt;li&gt;Where can I find Hardware/Power Specifications for the WFR Series?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;For the Web Filter, please see the &lt;a href="https://support.levelblue.com/software/8e6/hd/Trustwave-wf-hd-specs.htm" class="ApplyClass" target="_blank"&gt;WF Hardware Specifications&lt;/a&gt; matrix.&lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;For the WFR, please see the &lt;a href="https://support.levelblue.com/software/8e6/hd/Trustwave-wfr-hd-specs.htm" class="ApplyClass" target="_blank"&gt;WFR Hardware Specifications&lt;/a&gt; matrix.&lt;p&gt;&lt;/p&gt;&lt;h2&gt;Note:&lt;/h2&gt;These documents refer to the hardware currently shipping as of the revision date on each document.&lt;br /&gt;&lt;p&gt;&lt;/p&gt;</description><pubDate>Wed, 17 Jul 2013 19:56:39 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item></channel></rss>