﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>LevelBlue Knowledge Base » Knowledgebase » Legacy Products » Secure Web Gateway » Proxy</title><generator>InstantKB.NET 2.0.6</generator><description>LevelBlue Knowledge Base</description><link>https://support.levelblue.com/kb/</link><webMaster>website@m86security.com</webMaster><lastBuildDate>Tue, 21 Apr 2026 19:58:38 GMT</lastBuildDate><ttl>20</ttl><item><title>Usage of external CA certificates</title><link>https://support.levelblue.com/kb/Goto14827.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;WebMarshal&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How can I use external CA certificate with WebMarshal?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Use of publicly trusted CA certificates in proxying end-user communications with internet systems is prohibited by some browser manufacturer rules and regulations.  LevelBlue recommends the use of a self signed or enterprise CA for proxying use. If you intend to use a publicly trusted or cross signed CA certificate with this product, consult with the issuing CA to ensure your use is compliant with all current and anticipated regulations.&lt;/p&gt;&lt;p&gt;To import a CA certificate, you can use the Certificate Converter Tool available from the &lt;a href="https://support.levelblue.com/webmarshal/upgrade.asp" target="_blank" class="ApplyClass"&gt;WebMarshal Download&lt;/a&gt; page.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><pubDate>Wed, 01 Apr 2020 00:00:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Why the Status Page is not displayed in Chrome browser when using FTP over HTTP?</title><link>https://support.levelblue.com/kb/Goto20384.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;All SWG versions&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Why the Status Page is not displayed in Chrome browser when using FTP over HTTP protocol? (when setting port 8080 in the proxy settings for FTP transactions on the browser side)&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;The header in the GET request coming from the browser which is mandatory for activating the Status Page is the User-Agent header. &lt;/p&gt;This is visible in the &lt;strong&gt;"Administration &amp;gt;  System Settings &amp;gt;  Scanning &amp;gt;  Scanning Options"&lt;/strong&gt; section of the SWG GUI (part of the configuration) - see the screenshot below:&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/20384/Status_Page_setting.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;Chrome browser doesn't include User-Agent header in the GET request when FTP over HTTP protocol is being used.&lt;br /&gt;Please see below the comparison of the GET requests that are sent by the browsers for retrieving the same file when using Chrome and Firefox:&lt;br /&gt;&lt;br /&gt;1) &lt;strong&gt;Chrome browser&lt;/strong&gt; - no User-Agent header is included in the GET request:&lt;br /&gt;&lt;br /&gt;&lt;img alt="" width="601" height="323" src="https://support.levelblue.com/kb/Uploads/Images/20384/Chrome_No_Status_Page.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;2) &lt;strong&gt;Firefox browser&lt;/strong&gt; - User-Agent header is included in the GET request:&lt;br /&gt;&lt;br /&gt;&lt;img alt="" width="601" height="337" src="https://support.levelblue.com/kb/Uploads/Images/20384/FF_Status_Page.PNG" /&gt;&lt;br /&gt;&lt;h2&gt; &lt;/h2&gt;&lt;h2&gt;Notes:&lt;/h2&gt;This article is applicable only when FTP over HTTP protocol is used (port 8080 for FTP transactions is set on the browser side in the proxy settings). For other protocols (e.g. HTTP etc.), the behavior is different.&lt;br /&gt;&lt;br /&gt;</description><pubDate>Wed, 16 Sep 2015 09:06:27 GMT</pubDate><dc:creator>Mariusz Cieślak</dc:creator></item><item><title>How to bypass Authentication by header</title><link>https://support.levelblue.com/kb/Goto14069.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x &lt;/li&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Some sites or programs require you to bypass Authentication in order for it to be accessed through the SWG appliance. For Example, Google Earth’s update mechanism will not allow the program to run if it cannot contact its host site, and the host site cannot be reached when using Authentication through the SWG. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt; &lt;/p&gt;&lt;ul&gt;    &lt;li&gt;To bypass authentication for our Google Earth example, we will bypass using the User-Agent header that Google Earth uses to access its host site. &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;-Navigate to Polices -&amp;gt; Condition Settings -&amp;gt; Header Fields &lt;/div&gt;&lt;div&gt;-Under Exclude by Headers click edit and enter the following information. &lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;/span&gt;Header Name: &lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;/span&gt;Condition: &lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;/span&gt;Header Value: &lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img alt="" style="height: 85px; width: 566px;" src="https://support.levelblue.com/kb/Uploads/Images/JB/Headerlayout.png" /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;- Save and Commit changes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*note: in VSOS 9.0.0 you cannot add more than one user agent header name to the same Headers Field list. If you need to add more than one user agent you will need to create a separate list for each user agent entry. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-Other programs and hardware have been known to need to have authentication bypassed in order to be used. Here is the program and the Header name used to allow access. &lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;table class="MsoTableLightListAccent1" style="border-top-style: none; width: 482.6pt; border-collapse: collapse; border-bottom-style: none; border-right-style: none; border-left-style: none;" cellspacing="0" cellpadding="0" width="643" border="1"&gt;    &lt;tbody&gt;        &lt;tr style="height: 16.35pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom-style: none; border-right-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Application&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-bottom-style: none; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Header&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-bottom-style: none; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Value&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 16.35pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;Google Earth&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;^GoogleEarth.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top-style: none; width: 117.9pt; border-bottom-style: none; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;iPhone&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 99pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 103.5pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Apple iPhone.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 16.35pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;iPad&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Apple iPad.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top-style: none; width: 117.9pt; border-bottom-style: none; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;iTunes&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 99pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 103.5pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;iTunes/.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 16.35pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;AppleCoreMedia/.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top-style: none; width: 117.9pt; border-bottom-style: none; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;Microsoft Updates&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 99pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 103.5pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Equals&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Windows-Update-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;^MicrosoftBITS/.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top-style: none; width: 117.9pt; border-bottom-style: none; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;Adobe Flash&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 99pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 103.5pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;^Adobe Flash Update.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt; &lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;&lt;br /&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;&lt;br /&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;&lt;br /&gt;            &lt;/td&gt;        &lt;/tr&gt;    &lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Mon, 27 Apr 2015 15:17:40 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>Why do some pages with cache kit enabled load slowly</title><link>https://support.levelblue.com/kb/Goto16504.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Why do some some pages load slowly with SWG caching kit installed and enabled?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;Some pages/HTTP servers are poorly designed and send confirmations for every page, script, or resource request in a non-parallel manner (one after another). In this example, note the many HTTP messages "HTTP/1.0 304 Not Modified".&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/899689/a1.png" style="width: 600px; height: 169px;" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;As you can see, the server is sending messages one after another; in this case it takes 16 seconds to load a small page with many js scripts:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/899689/2.png" style="width: 600px; height: 282px;" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;HOW to fix the issue:&lt;/h2&gt;&lt;p&gt;Because it is not an SWG related problem, you must exclude this type of site from caching; add an exception as shown below:&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/899689/3.png" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><pubDate>Wed, 05 Feb 2014 01:17:01 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Does Dropbox work with SWG SSL scanning?</title><link>https://support.levelblue.com/kb/Goto14437.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Does Dropbox work with SWG SSL scanning?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;Yes, but the only way that drop box will work with the SWG is if SSL scanning is bypassed for Dropbox. In the dropbox help it is suggested that you create an HTTPS bypass list that you can add Dropbox to so that it will not be scanned by the SWG. &lt;/p&gt;&lt;p&gt;Dropbox was not designed to work with an SLL proxy. When drop box makes a connection to the client it refuses to use the OS root SSL certificates that’s provided to the drop box client (which is what the SWG uses in the event of a HTTPS connect). It then sends an encrypted alert stating that the certificate that is being served is “bad” and ends the connection. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;&lt;span style="line-height: 115%; font-size: 9pt; font-family: arial, sans-serif;"&gt;Drop box help:&lt;/span&gt;&lt;span class="apple-converted-space" style="line-height: 115%; font-size: 9pt; font-family: arial, sans-serif;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;span style="line-height: 115%; font-size: 9pt; font-family: arial, sans-serif;"&gt;“You have a proxy orfirewall blocking the Dropbox service&lt;/span&gt;&lt;span class="apple-converted-space" style="line-height: 115%; font-size: 9pt; font-family: arial, sans-serif;"&gt; &lt;/span&gt;&lt;span style="line-height: 115%; font-size: 9pt; font-family: arial, sans-serif;"&gt;Dropboxuses standard internet ports (80 and 443) to transfer data. However, manyfirewalls and security software will proactively block unauthorized or unknowninternet services. Add Dropbox to your proxy orfirewall settings as anexception to connect to the Dropbox service. “&lt;/span&gt;&lt;span class="apple-converted-space" style="line-height: 115%; font-size: 9pt; font-family: arial, sans-serif;"&gt; &lt;/span&gt;&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 24 Nov 2013 03:53:55 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Check or Change Trustwave Filter List Categorization</title><link>https://support.levelblue.com/kb/Goto16271.aspx</link><description>&lt;p class="MsoNormal" style="font-size: 11px; line-height: normal;"&gt;&lt;strong&gt;&lt;span style="font-size: 18pt; font-family: verdana, sans-serif;"&gt;This article applies to:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul style="font-size: 11px; line-height: 12px;"&gt;    &lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;SWG 10.1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;    &lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;SWG 10.2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;    &lt;li class="MsoNormal" style="line-height: normal;"&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;SWG 11.x&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="font-size: 11px; line-height: normal;"&gt;&lt;strong&gt;&lt;span style="font-size: 18pt; font-family: verdana, sans-serif;"&gt;Question:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul style="font-size: 11px; line-height: 12px;"&gt;    &lt;li class="MsoNormal" style="line-height: 12px;"&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;How can you check the classification of a URL in the Trustwave Filter List database? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="font-size: 11px; line-height: normal;"&gt;&lt;strong&gt;&lt;span style="font-size: 18pt; font-family: verdana, sans-serif;"&gt;Information:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="font-size: 11px; line-height: normal;"&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;It may happen that a given link is wrongly categorized. In addition, a URL can &lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;sometimes&lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;change owner and website content. &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="font-size: 11px; line-height: 12px;"&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;You can check a site category in the Trustwave &lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;Filter List &lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;database, or submit a site to Trustwave if it n&lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;eeds to be added to the database or reviewed for a possible mistake in categorization. &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="font-size: 11px; line-height: normal;"&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;Go to:&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="font-size: 11px; line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span lang="EN-US" style="color: blue;"&gt;&lt;a href="https://support.levelblue.com/m86filtercheck.asp"&gt;https://support.levelblue.com/m86filtercheck.asp&lt;/a&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="font-size: 11px; line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: 8pt; font-family: verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="font-size: 11px; line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: 8pt; font-family: verdana, sans-serif;"&gt;You can also v&lt;/span&gt;&lt;span style="font-size: 8pt; line-height: normal; font-family: verdana, sans-serif;"&gt;iew a list of categories and their definitions.&lt;/span&gt;&lt;/p&gt;</description><pubDate>Thu, 14 Nov 2013 04:36:11 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>SWG support for HTTP HEAD requests </title><link>https://support.levelblue.com/kb/Goto16140.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Will an SWG proxy honor HTTP HEAD requests ?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;An HTTP HEAD request is very similar to an HTTP GET request, the difference being that it asks the Server to return the response headers only, and not the actual resource itself.&lt;/p&gt;&lt;p&gt;This method is useful when the resource needs to be evaluated without actually downloading it, saving bandwidth for example. &lt;/p&gt;&lt;p&gt;SWG supports the HTTP HEAD method without any specific configuration changes, and by default the transactions shown below &lt;span style="line-height: 12px;"&gt;are allowed&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;     &lt;img alt="" style="width: 575px; height: 111px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/16140/head_cli_01.png" /&gt;&lt;/p&gt;&lt;p&gt;If needed, a custom rule may be added to the policy to block HTTP HEAD requests, using the HTTP Method condition:&lt;/p&gt;&lt;p&gt;     &lt;img alt="" style="width: 575px; height: 342px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/16140/head_policy.PNG" /&gt;&lt;/p&gt;&lt;p&gt;This is how an SWG proxy works when an HTTP HEAD request is blocked by the policy:&lt;/p&gt;&lt;p&gt;     &lt;img alt="" style="width: 575px; height: 86px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/16140/head_cli_02.png" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;     &lt;img alt="" style="width: 575px; height: 333px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/16140/head_logs_02.png" /&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;</description><pubDate>Tue, 24 Sep 2013 08:33:51 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>How to backup SWG</title><link>https://support.levelblue.com/kb/Goto16088.aspx</link><description>&lt;strong style="font-size: medium;"&gt;This article applies to:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 18px;"&gt;SWG 10.x&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 18px;"&gt;SWG 11.x&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size: 16px;"&gt;&lt;strong&gt;Question:&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;How do I create a backup of my SWG settings and configuration?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 16px;"&gt;&lt;strong&gt;Procedure:&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;There is a feature in SWG called "Backup" (or "Rollback" in SWG version 10.x.) This feature allows you to create a backup file of your SWG where it can be saved in an alternate location (backups are not saved locally on the SWG).  A backup consists of all data that an administrator can customize in the Management Console (including Policies, Settings etc.).&lt;br /&gt;&lt;br /&gt;To create a rollback:&lt;div&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;In SWG 10.x, navigate to &lt;/span&gt;&lt;strong style="font-size: 8pt;"&gt;Administration &amp;gt; Rollback &amp;gt; Rollback Settings&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;In SWG 11.x, navigate to &lt;/span&gt;&lt;strong style="font-size: 8pt;"&gt;Administration &amp;gt; Policy Server DB Backup &amp;gt; Backup Settings&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;From here you can configure a connection method location and scheduling for the backup. If you have any trouble in configuring the backup, click the "?" or &lt;strong&gt;F1&lt;/strong&gt; Help button to see additional information about backup settings.&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration: underline;"&gt;Why is backup helpful?&lt;/span&gt; In the event of a critical system failure where the SWG is not recoverable, the SWG system can be re-imaged to its default factory settings. After it has been reset to its factory settings, the last saved backup can be applied to the system restoring the custom configuration and settings.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 16px;"&gt;Note:&lt;/span&gt;&lt;br /&gt;System backups do not include information in the LogServer database, Reports Server database (see &lt;strong style="font-size: 8pt;"&gt;Administration &amp;gt; Reports DB Backup &amp;gt; Backup Settings&lt;/strong&gt;&lt;span style="font-size: 8pt;"&gt;)&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;, Custom Block Messages, and Updates.  &lt;/span&gt;&lt;/div&gt;</description><pubDate>Tue, 24 Sep 2013 08:31:31 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Allow (bypass) Audio Streaming through SWG</title><link>https://support.levelblue.com/kb/Goto14366.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Audio streams (e.g. Web Radio) do not work through the SWG, and there are no log entries.&lt;/li&gt;    &lt;li&gt;I have an "Allow Streaming" rule, but audio streaming does not work and the logs don't show anything being Blocked. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;Audio streaming formats are not included in "Allow streaming" rule by default.&lt;/p&gt;&lt;p&gt;In order to allow (actually, to bypass) these formats, modify the rule conditions by selecting 'Audio File' as shown below:&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/14366/14366_01.jpg" /&gt;&lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Tue, 24 Sep 2013 08:21:13 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Incorrect Policy enforcement for Windows 7 / Windows Vista users due to the NCSI feature</title><link>https://support.levelblue.com/kb/Goto15205.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;    &lt;li&gt;Users running &lt;span style="font-size: 11px; line-height: 12px;"&gt;Microsoft &lt;/span&gt;Windows Vista or &lt;span style="font-size: 11px; line-height: 12px;"&gt;Microsoft &lt;/span&gt;Windows 7&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;p&gt;S&lt;span style="line-height: 12px;"&gt;ymptoms may vary d&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;epending on SWG identification implementation.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;In some cases, when the user first boots into the Windows OS they get a message from Microsoft Networking with a yellow exclamation icon in the system tray. &lt;/p&gt;&lt;p&gt;The error message that opens is "No Internet Access".&lt;/p&gt;&lt;p&gt;T&lt;span style="line-height: 12px;"&gt;he yellow exclamation icon goes away a&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;s soon as the user opens Internet Explorer.&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;    &lt;/ul&gt;    &lt;p&gt;Another variation is that the users are identified as Unknown Users, and as a result the incorrect security policy is enforced for such users.&lt;/p&gt;    &lt;div&gt;This can be verified in the Web Logs view showing Authenticated User Names containing '$' signs:&lt;/div&gt;    &lt;div&gt;&lt;br /&gt;    &lt;/div&gt;    &lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;       &lt;img alt="" style="width: 580px; height: 266px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15205/01.png" /&gt;&lt;/span&gt;&lt;/div&gt;    &lt;h2&gt;Causes:&lt;/h2&gt;    This behavior is unique to Window Vista and Windows 7 OS versions after the Network Connectivity Status Indicator (NCSI) feature was introduced in Windows Vista.&lt;br /&gt;    NCSI is designed to be responsive to network conditions, so it examines the connectivity of a network in a variety of ways. Once a test fails, NCSI may report an error, even if the network can &lt;span style="font-size: 11px; line-height: 18px;"&gt;actually &lt;/span&gt;be fully accessed.  &lt;br /&gt;    For example, NCSI tests connectivity by trying to connect to http://www.msftncsi.com, a simple website that exists only to support the functionality of NCSI. &lt;br /&gt;    &lt;br /&gt;    &lt;div&gt;Try to manually visit the website http://www.msftncsi.com/ncsi.txt. You should see “Microsoft NCSI”:&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/15205/NCSI.PNG" /&gt;&lt;br /&gt;    &lt;br /&gt;    A proxy server requiring user authentication won't allow it to access the Internet.&lt;br /&gt;    &lt;h2&gt;Resolution:&lt;/h2&gt;    &lt;p&gt;There are two ways to resolve this issue:&lt;/p&gt;    &lt;p&gt;1. By bypassing *.msftncsi.com/* for Authentication purposes.&lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;2. By modifying registry settings to disable the NCSI functionality:&lt;/p&gt;    &lt;p&gt;   - Run regedit (administrative permission is required)&lt;/p&gt;    &lt;p&gt;   - Navigate to the following key:&lt;/p&gt;    &lt;p&gt;     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\&lt;/p&gt;    &lt;p&gt;   - Locate EnableActiveProbing parameter&lt;/p&gt;    &lt;p&gt;   - Allowed values: 1 - Enable NCSI, 0 - Disable NCSI &lt;/p&gt;    &lt;p&gt;    &lt;img alt="" style="width: 580px; height: 283px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15205/02.png" /&gt;&lt;/p&gt;    &lt;p&gt;These registry settings can be distributed globally as part of the Group Policy push from the Domain Controller.&lt;/p&gt;    &lt;h2&gt;&lt;/h2&gt;    &lt;/div&gt;</description><pubDate>Mon, 19 Aug 2013 06:35:52 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>When we tunnel HTTPS, why can we block a page but not show the block page?</title><link>https://support.levelblue.com/kb/Goto16021.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;    &lt;p class="MsoNormal"&gt;When we tunnel HTTPS traffic over HTTP (user browser has 8080 on all protocols), we can still block the HTTPS site request via URL cat and URL list, but the Block page does not display. Instead of a regular Block page, in Firefox we get "The proxy server is refusing connections". But we still see the Web log with the correct block reason.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;Why can we block but not show the Block page when we tunnel HTTPS?&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;This is a normal browser behavior. That is, if you look at the capture you will see that SWG is sending the 403 error page correctly.&lt;/p&gt;&lt;p&gt;However, the browser is rendering it differently and showing its own error message. Browsers do not apply 403 error messages over HTTPS, only over HTTP.&lt;/p&gt;&lt;p&gt;This is not an SWG issue, but a security feature in all browsers.&lt;/p&gt;&lt;p&gt;You can see this in the Firefox bug report: &lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id=493699#c1" class="ApplyClass"&gt;https://bugzilla.mozilla.org/show_bug.cgi?id=493699#c1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and in the Chrome bug system: &lt;a href="https://code.google.com/p/chromium/issues/detail?id=62993#c1"&gt;https://code.google.com/p/chromium/issues/detail?id=62993#c1&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Sun, 28 Jul 2013 04:11:01 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Web Logs show IP addresses for requested URL(s)</title><link>https://support.levelblue.com/kb/Goto16025.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG transparent implementation - WCCP, Bridge, transparent gateway &lt;/li&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;When looking in the Web Logs, why are almost all HTTPS transactions being logged for IP addresses instead of URL(s)? &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;       &lt;img alt="" style="width: 469px; height: 600px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/16025/logs.png" /&gt;&lt;/p&gt;&lt;ul&gt;&lt;/ul&gt;    &lt;h2&gt;Information:&lt;/h2&gt;    With SWG implemented in Transparent Mode, URL resolution is performed by the client issuing a request, and not by the scanner.&lt;br /&gt;    As a result, when such a request comes in, SWG has to rely on the information sent by the client.&lt;br /&gt;    For HTTP traffic, SWG extracts URL information from the host header present in the HTTP GET request.&lt;br /&gt;    This however, is not available for SSL traffic, and as a result SWG presents IP addresses instead of URL addresses.&lt;br /&gt;    &lt;br /&gt;    There is a way to obtain URL/hostname information for a request using the certificate data associated with it.&lt;br /&gt;    Navigate to &lt;strong&gt;Administration &amp;gt;  System Settings &amp;gt;  SWG Devices.&lt;/strong&gt; Then under &lt;strong&gt;Scanning Server&lt;/strong&gt;, go to &lt;strong&gt;General &amp;gt; Transparent Proxy Mode&lt;/strong&gt; tab. Enable the &lt;strong&gt;Extract hostname from certificate&lt;/strong&gt; option, as shown below.&lt;br /&gt;    This setting is present on Scanning Server only.&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" style="width: 600px; height: 314px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/16025/hostname-cert.PNG" /&gt;&lt;br /&gt;    &lt;br /&gt;    With this setting enabled, the logs show both IP and URL addresses per a request:&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" style="width: 285px; height: 179px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/16025/new-logs-01.PNG" /&gt;     &lt;img alt="" style="width: 284px; height: 179px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/16025/new-logs-02.PNG" /&gt;&lt;br /&gt;</description><pubDate>Sun, 28 Jul 2013 04:08:20 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Use custom rules to bypass scanning for large files</title><link>https://support.levelblue.com/kb/Goto15957.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Download is blocked and the following message is presented to the user: &lt;/li&gt;&lt;/ul&gt;&lt;blockquote style="border: medium none; padding: 0px; margin: 0px 0px 0px 40px;"&gt;&lt;div&gt;&lt;p style="line-height: normal; font-size: 11px;"&gt;Error Occurred &lt;/p&gt;&lt;/div&gt;&lt;div&gt;&lt;p style="line-height: normal; font-size: 11px;"&gt;HTTP Error Status: 403 Forbidden&lt;/p&gt;&lt;/div&gt;&lt;div&gt;&lt;p style="line-height: normal; font-size: 11px;"&gt;Error Reason: Response body too large Please contact your system administrator&lt;/p&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;h2&gt;Cause:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG proxy is limited to downloading/uploading files up to 2GB in size. This limit is configured in the &lt;strong&gt;Downloads&lt;/strong&gt; tab under &lt;strong&gt;Administration &amp;gt; System Settings &amp;gt; SWG&lt;/strong&gt; &lt;strong&gt;Devices &amp;gt; Scanning Server &amp;gt; General&lt;/strong&gt; node: &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span style="white-space: pre;" class="Apple-tab-span"&gt;&lt;/span&gt;&lt;img alt="" style="width: 600px; height: 200px; font-size: 8pt;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15957/downloads.png" /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;If SWG proxy is expected to deal with many large files, it may help to bypass scanning for those files. This can be done by creating two additional rules in the Security Policy, as detailed below.&lt;/p&gt;&lt;div&gt;&lt;br /&gt;Both the rules make sure that the files are not scanned. &lt;span style="line-height: 12px;"&gt;The first rule allows the file to download through SWG immediately, while the second rule needs to download the file first to evaluate the content size.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It is important to position these rules properly in the policy. &lt;span style="line-height: 12px;"&gt;For better performance, place the rules below the &lt;/span&gt;&lt;strong style="font-size: 8pt;"&gt;Allow Trusted Sites&lt;/strong&gt;&lt;span style="line-height: 12px;"&gt; and &lt;/span&gt;&lt;strong style="font-size: 8pt;"&gt;Block Blacklisted Sites&lt;/strong&gt;&lt;span style="line-height: 12px;"&gt; rules.&lt;/span&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;&lt;h3&gt;First Rule&lt;/h3&gt;&lt;p&gt;The first rule should bypass scanning for large files based on the value in the content-length header field associated with the file in the transaction.&lt;/p&gt;&lt;p&gt;1. Create a custom HTTP header as shown below. Set the value relevant to your SWG implementation: &lt;span style="line-height: 12px;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px;"&gt;     &lt;img alt="" style="width: 600px; height: 244px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15957/mcontent-length.png" /&gt;&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px;"&gt;    N&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;ote that the content-length header value should be set in bytes.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;2. Create a new rule in the policy and add the new custom header as a condition for the rule.&lt;/p&gt;&lt;p&gt;     &lt;img alt="" style="width: 600px; height: 394px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15957/rule-cl.PNG" /&gt;&lt;/p&gt;&lt;p&gt;3. Make sure the rule &lt;strong&gt;Action&lt;/strong&gt; is set to &lt;strong&gt;Allow &lt;/strong&gt;and &lt;strong&gt;Advanced Action&lt;/strong&gt; is set to &lt;strong&gt;Bypass scanning&lt;/strong&gt;:&lt;/p&gt;&lt;p&gt;     &lt;img alt="" style="width: 600px; height: 229px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15957/rule-adv.PNG" /&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;h3&gt;Second Rule&lt;/h3&gt;&lt;p&gt;It is possible that a file in a Web transaction will not have a content-length header specified for it. As a result, the rule we just created will not bypass scanning for such file.&lt;/p&gt;&lt;p&gt;For this reason we need a second rule to bypass scanning for large files based on the content size value. &lt;/p&gt;&lt;p&gt;1. Use one of the default Content Size conditions available in the SWG OS, or create a new one to make it consistent with the rule above.&lt;/p&gt;&lt;blockquote style="border: medium none; padding: 0px; margin: 0px 0px 0px 40px;"&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;Content Size conditions are under: &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;Version 10.x: &lt;strong&gt;Policies &lt;/strong&gt;&amp;gt; &lt;strong&gt;Condition Settings&lt;/strong&gt; &amp;gt; &lt;strong&gt;Content Size&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;Version 11.x: &lt;strong&gt;Policies&lt;/strong&gt; &amp;gt; &lt;strong&gt;Condition Elements&lt;/strong&gt; &amp;gt; &lt;strong&gt;Content Size&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;    &lt;img alt="" style="width: 600px; height: 210px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15957/content-size.PNG" /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px;"&gt;2. Create a new rule in the policy and use Content Size as a condition for the rule.&lt;/span&gt;&lt;/p&gt;&lt;div&gt;    &lt;img alt="" style="width: 600px; height: 396px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15957/rule-cs.PNG" /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 12px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 12px;"&gt;&lt;h2 style="line-height: 18px;"&gt;Notes:&lt;/h2&gt;&lt;div&gt;&lt;strong&gt;Important:&lt;/strong&gt; Content-length header value is set in bytes, content-size condition value is set in kilobytes.&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Mon, 08 Jul 2013 02:23:38 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>How to bypass Authentication by header</title><link>https://support.levelblue.com/kb/Goto14067.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Some sites or programs require you to bypass Authentication in order for it to be accessed through the SWG appliance. For example, Google Earth’s update mechanism will not allow the program to run if it cannot contact its host site, and the host site cannot be reached when using Authentication through the SWG. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;To bypass authentication in our Google Earth example, we will use the User-Agent header that Google Earth uses to access its host site. &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;ol&gt;    &lt;li&gt;Navigate to &lt;strong&gt;Polices &amp;gt; Condition Settings &amp;gt; Header Fields&lt;/strong&gt;. &lt;/li&gt;    &lt;li&gt;Under &lt;strong&gt;Exclude by Headers&lt;/strong&gt;, click &lt;strong&gt;Edit&lt;/strong&gt; and enter the following information: &lt;/li&gt;&lt;/ol&gt;&lt;blockquote style="margin-right: 0px;" dir="ltr"&gt;&lt;div&gt;&lt;span style="white-space: pre;" class="Apple-tab-span"&gt;&lt;/span&gt;Header Name: &lt;/div&gt;&lt;div&gt;&lt;span style="white-space: pre;" class="Apple-tab-span"&gt;&lt;/span&gt;Condition: &lt;/div&gt;&lt;div&gt;&lt;span style="white-space: pre;" class="Apple-tab-span"&gt;&lt;/span&gt;Header Value: &lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img alt="" style="width: 566px; height: 85px;" src="https://support.levelblue.com/kb/Uploads/Images/JB/Headerlayout.png" /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;blockquote style="margin-right: 0px;" dir="ltr"&gt;&lt;div&gt;3. Save and Commit changes.&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 12px;"&gt;Other programs and hardware are known to need to have authentication bypassed in order to be used. Here are the programs and the Header names used to allow access. &lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;table border="0" cellpadding="0" cellspacing="0" style="border-collapse: collapse; width: 448pt;" class="telerik-reTable-2"&gt;    &lt;colgroup&gt;&lt;col width="88" style="width: 66pt;" /&gt;    &lt;col width="69" style="width: 52pt;" /&gt;    &lt;col width="210" style="width: 158pt;" /&gt;    &lt;col width="229" style="width: 172pt;" /&gt;    &lt;/colgroup&gt;    &lt;thead&gt;    &lt;/thead&gt;    &lt;tbody&gt;        &lt;tr height="21" style="height: 15.75pt; line-height: 12px;" class="telerik-reTableHeaderRow-2"&gt;            &lt;td class="telerik-reTableHeaderFirstCol-2" align="left" style="height: 15.75pt; width: 66pt;"&gt;Application&lt;/td&gt;            &lt;td class="telerik-reTableHeaderOddCol-2" style="border-left-style: none; width: 52pt;"&gt;Header&lt;/td&gt;            &lt;td class="telerik-reTableHeaderEvenCol-2" align="left" style="border-left-style: none; width: 158pt;"&gt;Value&lt;/td&gt;            &lt;td class="telerik-reTableHeaderOddCol-2" style="border-left-style: none; width: 172pt;"&gt;Expression&lt;/td&gt;        &lt;/tr&gt;        &lt;tr height="29" style="height: 21.75pt; line-height: 12px;" class="telerik-reTableOddRow-2"&gt;            &lt;td class="telerik-reTableFirstCol-2" align="left" style="height: 21.75pt; width: 66pt;"&gt;Google Earth&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" style="border-left-style: none; width: 52pt;"&gt;User-Agent&lt;/td&gt;            &lt;td class="telerik-reTableEvenCol-2" align="left" style="border-left-style: none; width: 158pt;"&gt;Regular            Expression&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" align="left" style="border-left-style: none; width: 172pt;"&gt;^GoogleEarth.*&lt;/td&gt;        &lt;/tr&gt;        &lt;tr height="29" style="height: 21.75pt; line-height: 12px;" class="telerik-reTableEvenRow-2"&gt;            &lt;td class="telerik-reTableFirstCol-2" align="left" style="height: 21.75pt; border-top-style: none; width: 66pt;"&gt;iPhone&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" style="border-top-style: none; border-left-style: none; width: 52pt;"&gt;User-Agent&lt;/td&gt;            &lt;td class="telerik-reTableEvenCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 158pt;"&gt;Regular Expression&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 172pt;"&gt;Apple iPhone.*&lt;/td&gt;        &lt;/tr&gt;        &lt;tr height="29" style="height: 21.75pt; line-height: 12px;" class="telerik-reTableOddRow-2"&gt;            &lt;td class="telerik-reTableFirstCol-2" align="left" style="height: 21.75pt; border-top-style: none; width: 66pt;"&gt;iPad&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" style="border-top-style: none; border-left-style: none; width: 52pt;"&gt;User-Agent&lt;/td&gt;            &lt;td class="telerik-reTableEvenCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 158pt;"&gt;Regular Expression&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 172pt;"&gt;Apple iPad.*&lt;/td&gt;        &lt;/tr&gt;        &lt;tr height="29" style="height: 21.75pt; line-height: 12px;" class="telerik-reTableEvenRow-2"&gt;            &lt;td class="telerik-reTableFirstCol-2" align="left" style="height: 21.75pt; border-top-style: none; width: 66pt;"&gt;iTunes&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" style="border-top-style: none; border-left-style: none; width: 52pt;"&gt;User-Agent&lt;/td&gt;            &lt;td class="telerik-reTableEvenCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 158pt;"&gt;Regular Expression&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 172pt;"&gt;iTunes/.*&lt;/td&gt;        &lt;/tr&gt;        &lt;tr height="21" style="height: 15.75pt; line-height: 12px;" class="telerik-reTableOddRow-2"&gt;            &lt;td class="telerik-reTableFirstCol-2" align="left" style="height: 15.75pt; width: 66pt;"&gt;-&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" style="border-left-style: none; width: 52pt;"&gt;-&lt;/td&gt;            &lt;td class="telerik-reTableEvenCol-2" align="left" style="border-left-style: none; width: 158pt;"&gt;-&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" align="left" style="border-left-style: none; width: 172pt;"&gt;AppleCoreMedia/.*&lt;/td&gt;        &lt;/tr&gt;        &lt;tr height="29" style="height: 21.75pt; line-height: 12px;" class="telerik-reTableEvenRow-2"&gt;            &lt;td class="telerik-reTableFirstCol-2" align="left" style="height: 21.75pt; border-top-style: none; width: 66pt;"&gt;Microsoft Updates&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" style="border-top-style: none; border-left-style: none; width: 52pt;"&gt;User-Agent&lt;/td&gt;            &lt;td class="telerik-reTableEvenCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 158pt;"&gt;Equals&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 172pt;"&gt;Windows-Update-Agent&lt;/td&gt;        &lt;/tr&gt;        &lt;tr height="21" style="height: 15.75pt; line-height: 12px;" class="telerik-reTableOddRow-2"&gt;            &lt;td class="telerik-reTableFirstCol-2" align="left" style="height: 15.75pt; width: 66pt;"&gt;-&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" style="border-left-style: none; width: 52pt;"&gt;-&lt;/td&gt;            &lt;td class="telerik-reTableEvenCol-2" align="left" style="border-left-style: none; width: 158pt;"&gt;Regular            Expression&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" align="left" style="border-left-style: none; width: 172pt;"&gt;^MicrosoftBITS/.*&lt;/td&gt;        &lt;/tr&gt;        &lt;tr height="29" style="height: 21.75pt; line-height: 12px;" class="telerik-reTableEvenRow-2"&gt;            &lt;td class="telerik-reTableFirstCol-2" align="left" style="height: 21.75pt; border-top-style: none; width: 66pt;"&gt;Adobe Flash&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" style="border-top-style: none; border-left-style: none; width: 52pt;"&gt;User-Agent&lt;/td&gt;            &lt;td class="telerik-reTableEvenCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 158pt;"&gt;Regular Expression&lt;/td&gt;            &lt;td class="telerik-reTableOddCol-2" align="left" style="border-top-style: none; border-left-style: none; width: 172pt;"&gt;^Adobe Flash Update.*&lt;/td&gt;        &lt;/tr&gt;    &lt;/tbody&gt;&lt;/table&gt;&lt;style type="text/css" id="telerik-reTable-2"&gt;    .telerik-reTable-2   {    border-collapse: collapse;    border: solid 0px;    font-family: Tahoma;    }    .telerik-reTable-2 tr.telerik-reTableHeaderRow-2     {    border-width: 1.0pt 1.0pt 3.0pt 1.0pt;    margin-top: 0in;    margin-right: 0in;    margin-bottom: 10.0pt;    margin-left: 0in;    line-height: 115%;    font-size: 11.0pt;    font-family: "Calibri","sans-serif";    width: 119.7pt;    border: solid white 1.0pt;    border-bottom: solid white 3.0pt;    background: #4F81BD;    padding: 0in 5.4pt 0in 5.4pt;    color: #FFFFFF;    }    .telerik-reTable-2 td.telerik-reTableHeaderFirstCol-2   {    border-width: 1.0pt 1.0pt 3.0pt 1.0pt;    border: solid white 1.0pt;    border-bottom: solid white 3.0pt;    padding: 0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 td.telerik-reTableHeaderLastCol-2  {    border-width: 1.0pt 1.0pt 3.0pt 1.0pt;    border: solid white 1.0pt;    border-bottom: solid white 3.0pt;    padding: 0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 td.telerik-reTableHeaderOddCol-2 {    border-width: 1.0pt 1.0pt 3.0pt 1.0pt;    border: solid white 1.0pt;    border-bottom: solid white 3.0pt;    padding: 0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 td.telerik-reTableHeaderEvenCol-2 {    border-width: 1.0pt 1.0pt 3.0pt 1.0pt;    border: solid white 1.0pt;    border-bottom: solid white 3.0pt;    padding: 0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 tr.telerik-reTableOddRow-2 {    color: #666666;    background-color: #F2F3F4;    font-size: 10pt;    vertical-align: top;    }    .telerik-reTable-2 tr.telerik-reTableEvenRow-2 {    color: #666666;    background-color: #E7EBF7;    font-size: 10pt;    vertical-align: top;    }    .telerik-reTable-2 td.telerik-reTableFirstCol-2  {    margin-top: 0in;    margin-right: 0in;    margin-bottom: 10.0pt;    margin-left: 0in;    line-height: 115%;    font-size: 11.0pt;    font-family: "Calibri","sans-serif";    width: 119.7pt;    border-top: none;    border-left: solid white 1.0pt;    border-bottom: none;    border-right: solid white 3.0pt;    background: #4F81BD;    padding: 0in 5.4pt 0in 5.4pt;    color: #FFFFFF;    }    .telerik-reTable-2 td.telerik-reTableLastCol-2 {    padding:0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 td.telerik-reTableOddCol-2  {    padding: 0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 td.telerik-reTableEvenCol-2 {    padding:0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 tr.telerik-reTableFooterRow-2    {    color: #666666;    background-color: #FFFFFF;    font-size: 10pt;    vertical-align: top;    padding: 0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 td.telerik-reTableFooterFirstCol-2  {    margin-top: 0in;    margin-right: 0in;    margin-bottom: 10.0pt;    margin-left: 0in;    line-height: 115%;    font-size: 11.0pt;    font-family: "Calibri","sans-serif";    width: 119.7pt;    border-top: none;    border-left: solid white 1.0pt;    border-bottom: none;    border-right: solid white 3.0pt;    background: #4F81BD;    padding: 0in 5.4pt 0in 5.4pt;    color: #FFFFFF;    }    .telerik-reTable-2 td.telerik-reTableFooterLastCol-2 {    padding: 0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 td.telerik-reTableFooterOddCol-2  {    padding: 0in 5.4pt 0in 5.4pt;    }    .telerik-reTable-2 td.telerik-reTableFooterEvenCol-2  {    padding: 0in 5.4pt 0in 5.4pt;    }&lt;/style&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Mon, 17 Jun 2013 01:26:10 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Signing CSR request and importing certificate for the scanner</title><link>https://support.levelblue.com/kb/Goto14525.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG v10.0&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;SWG v10.1&lt;/span&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;div&gt;This article describes detailed instructions on how to:&lt;/div&gt;&lt;ul&gt;    &lt;li&gt;Generate CSR request for Scanning Server using Trustwave SWG Web interface&lt;/li&gt;    &lt;li&gt;Submit CSR request data using MS PKI Web interface &lt;/li&gt;    &lt;li&gt;Import certificate information into &lt;span style="line-height: 12px; font-size: 11px;"&gt;Trustwave SWG Scanning Server&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;1.   Navigate to the Devices section in Trustwave SWG GUI, right-click the HTTPS module on the scanner and choose Generate Certificate option:&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/01.png" style="width: 503px; height: 339px;" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;2.   Choose CSR Certificate Type in the right pane and fill in all relevant details:&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/02.png" style="width: 496px; height: 315px;" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;3.   System responds with "Operation Succeeded" message, with the CSR request data in the background. Click OK and copy CSR data as simple text data.&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/03.png" style="width: 403px; height: 225px;" /&gt;&lt;/p&gt;&lt;p&gt;4.   &lt;span style="line-height: 12px; font-size: 11px;"&gt;Commit the changes. Do not create new CSR requests for other devices managed under same Policy Server.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;5.   Navigate to the MS-PKI Web GUI and select "Request a certificate" task:&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/04.png" /&gt;&lt;/p&gt;&lt;p&gt;6.   Submit advanced certificate request:&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/05.png" /&gt;&lt;/p&gt;&lt;p&gt;7.   Choose the option to submit CSR by using a base-64-encoded CMC or PKCS#10 file:&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/06.png" /&gt;&lt;/p&gt;&lt;p&gt;8.   Paste CSR data that was copied in step 3 above.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p style="font-size: 11px; line-height: 12px;"&gt;      Before submitting a request make sure Certificate Template is set to use Subordinate Certification Authority and "CA:TRUE" is set as Additional Attribute.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/07.png" /&gt;&lt;/p&gt;&lt;p&gt;9.   Select Base 64 encoded option and download certificate:&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/08.png" /&gt;&lt;/p&gt;&lt;p&gt;10.   Save the certificate on your system:&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/09.png" /&gt;&lt;/p&gt;&lt;p&gt;11. Open this certificate using text editor and copy the data as simple text data:&lt;/p&gt;&lt;p&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/10.png" /&gt;&lt;/p&gt;&lt;p&gt;12. Navigate to the Devices section in Trustwave SWG GUI, &lt;span style="line-height: 12px; font-size: 11px;"&gt;right-click the HTTPS module on the scanner and choose Import Certificate option:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/11.png" style="width: 500px; height: 338px;" /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;13. &lt;/span&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;Choose CSR Certificate Type in the right pane and paste in certificate data that was copied in step 10 above:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;      &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14525/12.png" /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;14. Commit changes. Certificate can now be exported from the device.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;If required to sign CSR certificate for more than one scanning server, it is important to perform above steps as separate procedure for every device. &lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Tue, 29 Jan 2013 23:59:01 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>How To Exclude Web Applications From the Authentication Mechanism</title><link>https://support.levelblue.com/kb/Goto13553.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;br /&gt;Some web applications (such as Citrix Webmeeting) get stuck due to authentication requests which can not be handled by such applications.&lt;br /&gt;This article describes how to exclude them from authentication mechanism.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;strong&gt;Symptoms&lt;/strong&gt;&lt;br /&gt;Example:&lt;br /&gt;Citrix Webmeeting gets stuck, or the connection setup wizard does not succeed.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;br /&gt;An authentication request is sent to the client in a later session stage, but the application cannot handle it correctly.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;br /&gt;The solution is to exclude this application / site from authentication mechanism.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Drawback:&lt;/strong&gt; The client is not authenticated or identified anymore and the policy for unknown users is applied.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. Step:&lt;/strong&gt; Create a list of URLs you want to exclude (It might be necessary to do a packet trace and analyze the destination URLs)&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/929~add_url-list.jpg" style="border-width: 0px; border-style: solid; " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Step:&lt;/strong&gt; add a condition to your authentication policy (it might be different from this example):&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/930~add_condition_1.jpg" style="border-width: 0px; border-style: solid; " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/931~add_condition_2.jpg" style="border-width: 0px; border-style: solid; " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Note:&lt;/strong&gt; This condition is based on URLs, basically other conditions such as header fields are also possible - it depends on the needs.&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/932~add_condition_3.jpg" style="border-width: 0px; border-style: solid; " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Step 3:&lt;/strong&gt; Commit your changes&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Note:&lt;/strong&gt; This option applies also to other identification policies (IP, Basic)&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;strong&gt;Software Version&lt;/strong&gt;&lt;br /&gt;9.x&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;dl style="margin-top: 10px; "&gt;    &lt;dt&gt;&lt;em&gt;This article applies to:&lt;/em&gt;&lt;/dt&gt;    &lt;dd&gt;&lt;em&gt;NG 1000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 5000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 6000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 8000&lt;/em&gt;&lt;/dd&gt;    &lt;em&gt;    &lt;/em&gt;&lt;/dl&gt;    &lt;em&gt;    &lt;dl style="margin-top: 10px; "&gt;        &lt;dt&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt;        &lt;/dt&gt;        &lt;dd&gt;&lt;em&gt;Finjan KB 1810&lt;/em&gt;        &lt;/dd&gt;    &lt;/dl&gt;    &lt;/em&gt;</description><pubDate>Fri, 31 Aug 2012 07:06:10 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Allow MSC to find nearest on-premise proxy</title><link>https://support.levelblue.com/kb/Goto14947.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Mobile Security Client (MSC)&lt;/li&gt;    &lt;li&gt;Secure Web Gateway&lt;/li&gt;    &lt;li&gt;MS Windows&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Problem Description:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;When there is more than one internal (on-premise) SWG proxy, the MSC is unable to work out which one is closest. This can lead to inefficient routing of web traffic and consequently poor browsing performance.&lt;/li&gt;    &lt;li&gt;For example, a company has two ‘main’ offices – one in NY and the other one in London. They have SWG scanners installed in both locations. They would like roaming users to use the local scanners when they are on premise. A few more ‘facts’:    &lt;ul&gt;        &lt;li&gt;NY scanners load balancer IP – 10.0.0.2&lt;/li&gt;        &lt;li&gt;London scanners load balancer IP – 192.168.120.5&lt;/li&gt;        &lt;li&gt;Each site has its own DNS server&lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Prerequisits:&lt;/h2&gt;&lt;p style="font-size: 11px; line-height: 12px; "&gt;Separate DNS servers covering each site are needed. If only one DNS server is used this solution will not work.&lt;/p&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p style="font-size: 11px; line-height: 12px; "&gt;How to make this work:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Define the following mapping in the DNS servers on both sites, so that the MSC software can detect that it is on premise:    &lt;ul&gt;        &lt;li&gt;Hostname ON-PREMISE-HOST &amp;gt; 1.1.1.1&lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Define in NY DNS server the following mapping:    &lt;ul&gt;        &lt;li&gt;Hostname SWG-SCANNING  &amp;gt; 10.0.0.2&lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Define in London DNS server the following mapping:    &lt;ul&gt;        &lt;li&gt;Hostname SWG-SCANNING &amp;gt; 192.168.120.5&lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;In the SWG Policy Server GUI, on the Proxies (On-premise) do the following:    &lt;ul&gt;        &lt;li&gt;Add the following line in the On-premise Proxy Details:        &lt;ul&gt;            &lt;li&gt;SWG-SCANNING              8080       8443&lt;/li&gt;        &lt;/ul&gt;        &lt;/li&gt;        &lt;li&gt;In the Corporate Hostname enter ON-PREMISE-HOST&lt;/li&gt;        &lt;li&gt;In the Internal Hostname IP enter 1.1.1.1 (or click the ‘Resolve IP’ button)&lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Commit the SWG policy update.&lt;/li&gt;    &lt;li&gt;Boot up the PC and allow the MSC run for a few minutes to identify and pull down its new configuration information.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;br class="Apple-interchange-newline" /&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;&lt;span lang="EN-GB" style="font-size: 11pt; line-height: 115%; font-family: calibri, sans-serif; "&gt;V0_1    2012-Aug-23&lt;/span&gt;&lt;/p&gt;</description><pubDate>Fri, 31 Aug 2012 06:50:55 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>SFG data mechanism and the use of 'Bypassed Context Scanning List' in SWG 10.x</title><link>https://support.levelblue.com/kb/Goto14946.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.1 comes with a new Scan Engine (Entrapper). Is the SFG Data Mechanism and the "Bypassed Context Scanning List" still in use?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;Inserting SFG Data tags to the page code was necessary in order to track and analyze a site in full context. If any problems occured with this, the solution was to add a site to the &lt;span style="font-size: 11px; line-height: 12px; "&gt;"Bypassed Context Scanning List". &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;SFG data is still being used in the product but in less scenarios than before. For example &lt;em&gt;java scripts&lt;/em&gt; are no longer marked with SFG since Entrapper (the new scan engine) now does pre-fetching, however, will still add SFG tags to &lt;em&gt;java applets&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;Due to the above, the need for this list has dramatically decreased but we still want to keep this functionality for other scenarios in case it creates a problem in the page.&lt;/p&gt;&lt;div style="font-size: 11px; line-height: 12px; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;-&lt;/p&gt;</description><pubDate>Wed, 29 Aug 2012 01:47:01 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>When downloading files, status page keeps reappearing or giving a 555 internal server error at the end</title><link>https://support.levelblue.com/kb/Goto14910.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x , 10.x , 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;When downloading files the download page keeps reappearing or giving a 555 internal server error at the end&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Causes:&lt;/h2&gt;With the limited shell command config_network, check if the scanners have an interface with the IP they have in the GUI-&amp;gt;Devices. &lt;br /&gt;The problem may lie with the fact that the scanners don't have an interfacewith the IP that you see in the GUI and a load balancer is used. The scanners assume they canconnect to each other with the IP seen in the GUI. &lt;br /&gt;&lt;br /&gt;The download with status page flow goes like this:&lt;br /&gt;&lt;ul&gt;    &lt;li&gt;Client requests file, via LB, from scanner A -&amp;gt;scanner A starts    the download and sends the status page to the client -&amp;gt; When    download/scan is complete the scanner sends a redirect response to the    client with a url pointing to the file location on the scanner and    parameter with the scanner ip. -&amp;gt; client follows the redirect url and    the LB directs it this time to scanner B -&amp;gt; scanner B checks if the    scanner IP address in the request parameter is his IP address.    &lt;ul&gt;        &lt;li&gt;If it is his IP address (A==B) , it returns the scanned file to the client&lt;/li&gt;        &lt;li&gt;If its not his IP address, it connects to that IP address (scanner A which holds the downloaded file) and streams the file back to the client.        &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ul&gt;In our test B was not A so it tried to connect to A and failed. Thiscaused the 555 - internal server error response, that was sent to theclient.&lt;br /&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;Two options:&lt;/p&gt;&lt;p&gt;&lt;ol&gt;    &lt;li&gt;Use a free network interface on each scanner to assign it the IP that we    see in the GUI, in a way they can connect to each other. e.g. As a VLAN that only the scanners can see.&lt;/li&gt;    &lt;li&gt;Disable the status page feature.&lt;/li&gt;&lt;/ol&gt;&lt;/p&gt;&lt;br /&gt;</description><pubDate>Thu, 09 Aug 2012 04:50:05 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>How to allow iTunes radio stations streaming contents</title><link>https://support.levelblue.com/kb/Goto14593.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;iTunes radio stations do not function properly with default security policy. With few changes listed below you could allow these contents through SWG proxy.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;First, it is possible that current security policy blocks initial requests for iTunes radio stations. All iTunes radio stations are being launched as PLS file, with further connection to a remote server. &lt;/p&gt;&lt;p&gt;This file extension is listed among M86 Recommended Forbidden File Extensions. &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;/span&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14593/pls.png" style="width: 498px; height: 324px; " /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px; "&gt;Review SWG web logs to validate if there are any blocks of Block Forbidden Extensions rule. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;If there are no blocks of this kind, continue with below article to modify the settings to allow iTunes radio station contents. &lt;br /&gt;If there are blocks of PLS file extension, make sure your security policy is set to allow PLS files.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;iTunes radio stations are streaming audio contents over the web, and it have to be allowed to stream contents in the same fashion that SWG allows video streaming.&lt;/p&gt;&lt;p&gt;Refer to the Allow Streaming rule in your security policy and make sure that Audio File True Content Type is checked as shown below:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;/span&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14593/audio_file.png" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It is also possible that some audio streaming would be using a custom Content-Type that would have to be allowed in a different way.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1. First, find out what these Content-Types are. This could be found in a network capture collected when a proxy was requested to deliver these streams.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 12px; font-size: 11px; "&gt;   &lt;/span&gt;&lt;span style="line-height: 12px; font-size: 11px; "&gt; &lt;/span&gt;Refer to Notes section below to find a KB on how to collect tcpdump network captures on a SWG device:&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 12px; font-size: 11px; "&gt;    &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 12px; font-size: 11px; "&gt;   &lt;/span&gt;&lt;span style="line-height: 12px; font-size: 11px; "&gt; &lt;/span&gt;Below example shows typical responses from the web server:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14593/contents.png" style="width: 583px; height: 216px; " /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;/span&gt;Note that SWG identifies above Content-Types as Audio File True Content Types, here it is only being used for demonstration purposes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;2. Navigate to the GUI section: Policy -&amp;gt; Condition Settings -&amp;gt; Header Fields, and create new Header Fields list, Audio Streaming, as shown below:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14593/header_list.png" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;3&lt;/span&gt;. Edit this Header Fields list to include the following two entries for above Content-Types:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14593/header_details.png" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;4&lt;/span&gt;. Navigate to the GUI section: Policy -&amp;gt; Security -&amp;gt; Advanced and review current security policy.&lt;/div&gt;&lt;div&gt;    &lt;/div&gt;&lt;div&gt;    Create new rule to Allow Streaming Contents based on Content-Types, and refer to the Header Fields list created in step 3:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14593/content_type_rule.png" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;/span&gt;J&lt;/span&gt;ust as with default Allow Streaming rule in M86 Security policies, make sure that this new rule is set with Advanced Action to Bypass Scanning and is located on top of the policy:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14593/allow.png" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;/span&gt;Save and commit the changes.&lt;/div&gt;&lt;h2&gt;&lt;/h2&gt;&lt;h2&gt;&lt;/h2&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;KB - How to run tcpdump trace on SWG device - &lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle14333.aspx" class="ApplyClass"&gt;https://support.levelblue.com/kb/KnowledgebaseArticle14333.aspx&lt;/a&gt;&lt;/p&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</description><pubDate>Thu, 24 May 2012 01:42:48 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Cannot POST a file bigger than 100MB</title><link>https://support.levelblue.com/kb/Goto14517.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x &lt;/li&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Cannot POST a file bigger than 100MB &lt;/li&gt;    &lt;li&gt;The error given is "Container Violation: Expanded file size limit exceeded" &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Causes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;There is a hard-coded limit to uploads of files that match specific MIME types, or are larger than 100MB &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;The workaround is to bypass scanning on uploads to one or more specified sites:&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Under Policies &amp;gt; Condition Settings &amp;gt; URL Lists, add a new List (such as "Bypassed Upload Scanning List") &lt;/li&gt;    &lt;li&gt;In this list, add the domains that you want to allow for large uploads (such as &lt;span style="font-family: 'courier new'; "&gt;"*.example.com/"&lt;/span&gt;). &lt;/li&gt;    &lt;li&gt;Save the List.  &lt;/li&gt;    &lt;li&gt;Under Policies &amp;gt; Security &amp;gt; Advanced Security policy, add a new Rule (such as "Bypass large uploads to example.com")    &lt;ul&gt;        &lt;li&gt;Set Action to Allow &lt;/li&gt;        &lt;li&gt;Set Advanced Action to Bypass Scanning &lt;/li&gt;        &lt;li&gt;Add a new Condition with Condition Name "URL Lists", "Any of..." selected, and select your new "Bypassed Upload Scanning List". &lt;/li&gt;        &lt;li&gt;Add a new Condition with Condition Name "Direction", "Any of..." selected, and select "Outgoing".  &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;    &lt;li&gt;Save the Rule.  &lt;/li&gt;    &lt;li&gt;For ease of reading, move the Rule near any other Allow Rules you may have. &lt;/li&gt;    &lt;li&gt;Commit the changes, and test. &lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;This limitation is currently planned for review in SWG version 11.&lt;/p&gt;</description><pubDate>Mon, 14 May 2012 02:01:49 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Silverlight Streaming through SWG</title><link>https://support.levelblue.com/kb/Goto14506.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG fails to pass Silverlight streams &lt;/li&gt;    &lt;li&gt;Silverlight does not work through SWG &lt;/li&gt;    &lt;li&gt;The SWG Status Page (displayed while downloads are being scanned) might be delivered to the Silverlight Player, but the Player may be unable to handle this page &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Testing:&lt;/h2&gt;&lt;p&gt;To determine if the status page is the issue, temporarily disable display of the status page:&lt;/p&gt;&lt;ol style="border-bottom-style: none; padding-bottom: 0px; border-right-style: none; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; padding-left: 0px; padding-right: 0px; border-top-style: none; border-left-style: none; padding-top: 0px; border-image: initial; "&gt;    &lt;li&gt;In the SWG GUI, navigate to Administration &amp;gt; Scanning &amp;gt; Scanning Options &lt;/li&gt;    &lt;li&gt;Deactivate "Enable Status Page" &lt;/li&gt;    &lt;li&gt;Commit &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Test the Silverlight player again. If the stream plays, then the player cannot handle the status page (which is sent to the client in the background).&lt;/p&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;To disable the status page only for this specific content:&lt;/p&gt;&lt;ol style="border-bottom-style: none; padding-bottom: 0px; line-height: 18px; border-right-style: none; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; padding-left: 0px; padding-right: 0px; border-top-style: none; border-left-style: none; padding-top: 0px; border-image: initial; "&gt;    &lt;li&gt;    &lt;div style="line-height: 12px; "&gt;In the SWG GUI, navigate to Administration &amp;gt; Scanning &amp;gt; Scanning Options&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div style="line-height: 12px; "&gt;Activate "Enable Status Page" again&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div style="line-height: 12px; "&gt;Select tab "Activate"&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div style="line-height: 12px; "&gt;Under "Unless" add the following (do not delete any existing items):&lt;/div&gt;    &lt;p style="margin-right: 0px; " dir="ltr"&gt;&lt;span style="font-family: 'courier new'; "&gt;Extension Is / &lt;strong&gt;xaml&lt;/strong&gt;&lt;br /&gt;    Extension Is / &lt;strong&gt;xap&lt;/strong&gt; &lt;br /&gt;    Extension Is / &lt;strong&gt;xbap&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p&gt;&lt;span style="font-family: 'courier new'; "&gt;Mime Type Contains / &lt;strong&gt;xaml+xml&lt;/strong&gt;&lt;br /&gt;    Mime Type Contains / &lt;strong&gt;x-silverlight-app&lt;br /&gt;    &lt;/strong&gt;Mime Type Contains / &lt;strong&gt;x-ms-xbap&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div style="line-height: 12px; "&gt;Commit&lt;/div&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;blockquote style="border-bottom-style: none; padding-bottom: 0px; border-right-style: none; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; padding-left: 0px; padding-right: 0px; border-top-style: none; border-left-style: none; padding-top: 0px; border-image: initial; "&gt;&lt;/blockquote&gt;</description><pubDate>Mon, 14 May 2012 01:58:54 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>How to configure FileZilla 3.x for use with FTP Proxy</title><link>https://support.levelblue.com/kb/Goto13497.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;strong&gt;Question&lt;/strong&gt;&lt;br /&gt;How do I configure FileZilla Client for use with the FTP Proxy (uploaded/downloaded files scanning, Native FTP)?&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;strong&gt;Answer&lt;/strong&gt;&lt;br /&gt;In order to set FileZilla to work with FTP Proxy, the following actions need to be taken:&lt;p&gt;1) Edit -&amp;gt; Settings -&amp;gt; FTP Proxy.&lt;br /&gt;&lt;br /&gt;2) Set Type of FTP Proxy to Custom and type:&lt;br /&gt;&lt;br /&gt;&lt;img alt="" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; " src="https://support.levelblue.com/kb/attachments/images/860~filezilla.jpg" /&gt;&lt;br /&gt;&lt;br /&gt;3) Set Proxy Host to the IP Address of your Scanner/Proxy IP and Port, seperated by colon - the default port is 2121.&lt;/p&gt;&lt;p&gt;&lt;img alt="" style="border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; " src="https://support.levelblue.com/kb/attachments/images/859~proxy_settings_filezilla.jpg" /&gt;&lt;/p&gt;4) Use the FTP client normally, all FTP session will be created via the proxy (scanner).&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;strong&gt;Software Version&lt;/strong&gt;&lt;br /&gt;not related to any SWG version&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;dl style="margin-top: 10px; "&gt;    &lt;dt&gt;&lt;em&gt;This article applies to:&lt;/em&gt;&lt;/dt&gt;    &lt;em&gt;FileZilla / Third party&lt;br /&gt;    &lt;/em&gt;&lt;/dl&gt;    &lt;dl style="margin-top: 10px; "&gt;        &lt;dt&gt;&lt;em&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt;        &lt;/em&gt;&lt;/dt&gt;        &lt;dd&gt;&lt;em&gt;&lt;em&gt;Finjan KB 1684&lt;/em&gt;        &lt;/em&gt;&lt;/dd&gt;    &lt;/dl&gt;</description><pubDate>Fri, 02 Mar 2012 03:31:01 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>EICAR virus file is not blocked</title><link>https://support.levelblue.com/kb/Goto14347.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.1&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;I am downloading eicar virus file via SWG and it is not blocked. Why is it not blocked?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;If cache is in use then this could be the reason.&lt;/p&gt;&lt;p&gt;The cache used by SWG is Squid. Squid sees that the virus file size is different than what it issupposed to be (1 byte difference) and therefore strips and does notpass the file content and you get a 0 size file which isnot a virus anymore and SWG does not have to block it.&lt;br /&gt;This is the correct behavior by Squid (according to RFC) even if a bit confusing.&lt;br /&gt;If you stop the cache, SWG will block it because size will not be zero.&lt;/p&gt;The behaviour described in this article only applies to the EICAR test virus. Actual viruses (not "&lt;span style="line-height: 12px; font-size: 11px; "&gt;0 size&lt;/span&gt;") are blocked correctly.</description><pubDate>Wed, 15 Feb 2012 06:02:36 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>ICAP Timeout Error When Browsing Through BlueCoat Proxy</title><link>https://support.levelblue.com/kb/Goto13558.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br /&gt;When browsing through a BlueCoat proxy with a Finjan scanner configured as an ICAP, client timeouts occurs. &lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br /&gt;&lt;p&gt;The following error is shown when trying to browse to a site:&lt;/p&gt;&lt;p&gt;&lt;em&gt;ICAP Error (icap_error)&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;An error occurred while performing an ICAP operation: Request timed out: Timed out while waiting for a response from the ICAP server.&lt;br /&gt;There could be a network problem, the ICAP service may be misconfigured, or the ICAP server may have reported an error.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;For assistance, contact your network support team.&lt;/em&gt; &lt;/p&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br /&gt;This is a result of a misconfigured default connection timeout value in the BlueCoat (That was changed in SGOS ver 5). &lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br /&gt;&lt;p&gt;To resolve this please increase the connection timeout for the RESP_MOD service as follows:&lt;/p&gt;&lt;p&gt;&lt;img alt="" style="border-bottom: 0px solid; border-left: 0px solid; border-top: 0px solid; border-right: 0px solid;" src="https://support.levelblue.com/kb/attachments/images/943~BC.png" /&gt;&lt;/p&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br /&gt;all SWG versions, but not related to &lt;/li&gt;&lt;/div&gt;&lt;dl style="margin-top: 10px;"&gt;    &lt;dt&gt;&lt;i&gt;This article applies to:&lt;/i&gt; &lt;/dt&gt;    &lt;dd&gt;&lt;i&gt;SWG 3000&lt;/i&gt; &lt;/dd&gt;    &lt;dd&gt;&lt;i&gt;SWG 5000&lt;/i&gt; &lt;/dd&gt;    &lt;dd&gt;&lt;i&gt;SWG 7000&lt;/i&gt; &lt;i&gt;    &lt;dl style="margin-top: 10px;"&gt;        &lt;dt&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt; &lt;/dt&gt;        &lt;dd&gt;&lt;i&gt;Finjan KB 1817&lt;/i&gt; &lt;/dd&gt;    &lt;/dl&gt;    &lt;/i&gt;&lt;/dd&gt;&lt;/dl&gt;</description><pubDate>Fri, 10 Dec 2010 09:07:11 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item></channel></rss>