﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>LevelBlue Knowledge Base » Knowledgebase » Legacy Products » Secure Web Gateway » Users and Authentication</title><generator>InstantKB.NET 2.0.6</generator><description>LevelBlue Knowledge Base</description><link>https://support.levelblue.com/kb/</link><webMaster>website@m86security.com</webMaster><lastBuildDate>Tue, 21 Apr 2026 19:44:55 GMT</lastBuildDate><ttl>20</ttl><item><title>How to bypass Authentication by header</title><link>https://support.levelblue.com/kb/Goto14069.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x &lt;/li&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Some sites or programs require you to bypass Authentication in order for it to be accessed through the SWG appliance. For Example, Google Earth’s update mechanism will not allow the program to run if it cannot contact its host site, and the host site cannot be reached when using Authentication through the SWG. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt; &lt;/p&gt;&lt;ul&gt;    &lt;li&gt;To bypass authentication for our Google Earth example, we will bypass using the User-Agent header that Google Earth uses to access its host site. &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;-Navigate to Polices -&amp;gt; Condition Settings -&amp;gt; Header Fields &lt;/div&gt;&lt;div&gt;-Under Exclude by Headers click edit and enter the following information. &lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;/span&gt;Header Name: &lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;/span&gt;Condition: &lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;/span&gt;Header Value: &lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img alt="" style="height: 85px; width: 566px;" src="https://support.levelblue.com/kb/Uploads/Images/JB/Headerlayout.png" /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;- Save and Commit changes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*note: in VSOS 9.0.0 you cannot add more than one user agent header name to the same Headers Field list. If you need to add more than one user agent you will need to create a separate list for each user agent entry. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-Other programs and hardware have been known to need to have authentication bypassed in order to be used. Here is the program and the Header name used to allow access. &lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;table class="MsoTableLightListAccent1" style="border-top-style: none; width: 482.6pt; border-collapse: collapse; border-bottom-style: none; border-right-style: none; border-left-style: none;" cellspacing="0" cellpadding="0" width="643" border="1"&gt;    &lt;tbody&gt;        &lt;tr style="height: 16.35pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom-style: none; border-right-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Application&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-bottom-style: none; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Header&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-bottom-style: none; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Value&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;&lt;strong&gt;&lt;span style="color: #ffffff;"&gt;Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 16.35pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;Google Earth&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;^GoogleEarth.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top-style: none; width: 117.9pt; border-bottom-style: none; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;iPhone&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 99pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 103.5pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Apple iPhone.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 16.35pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;iPad&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Apple iPad.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top-style: none; width: 117.9pt; border-bottom-style: none; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;iTunes&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 99pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 103.5pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;iTunes/.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 16.35pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;AppleCoreMedia/.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top-style: none; width: 117.9pt; border-bottom-style: none; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;Microsoft Updates&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 99pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 103.5pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Equals&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Windows-Update-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;^MicrosoftBITS/.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top-style: none; width: 117.9pt; border-bottom-style: none; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;Adobe Flash&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 99pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing" style="text-align: center;"&gt;User-Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; width: 103.5pt; border-bottom-style: none; padding-bottom: 0in; padding-top: 0in; border-right-style: none; padding-left: 5.4pt; border-left-style: none; padding-right: 5.4pt;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;Regular Expression&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top-style: none; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom-style: none; border-left-style: none;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt;^Adobe Flash Update.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;/td&gt;        &lt;/tr&gt;        &lt;tr style="height: 17.25pt;"&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 117.9pt; border-bottom: #4f81bd 1pt solid; border-right-style: none; border-left: #4f81bd 1pt solid;" valign="top"&gt;            &lt;p class="MsoNoSpacing"&gt; &lt;/p&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 99pt; border-right-style: none; border-left-style: none;" valign="top"&gt;&lt;br /&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; width: 103.5pt; border-right-style: none; border-left-style: none;" valign="top"&gt;&lt;br /&gt;            &lt;/td&gt;            &lt;td style="border-top: #4f81bd 1pt solid; border-right: #4f81bd 1pt solid; width: 162.2pt; border-bottom: #4f81bd 1pt solid; border-left-style: none;" valign="top"&gt;&lt;br /&gt;            &lt;/td&gt;        &lt;/tr&gt;    &lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Mon, 27 Apr 2015 15:17:40 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>In some scenarios SWG does not recognize LDAP users</title><link>https://support.levelblue.com/kb/Goto16490.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;In some scenarios SWG does not recognize LDAP users, even if they are in an imported group.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;If a customer adds a user/users after importing user/users group, the user/users won't be in the SWG database.&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 8pt;"&gt;Use scheduled updating of LDAP/AD users or manually import users after &lt;/span&gt;&lt;span style="font-size: 8pt; line-height: 18px;"&gt;any changes that you make to the LDAP tree structure (for example, adding/removing &lt;/span&gt;&lt;span style="font-size: 8pt; line-height: 18px;"&gt;groups, changing their order), or the changes will not be applied.&lt;/span&gt;&lt;/p&gt;</description><pubDate>Wed, 05 Feb 2014 01:20:06 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Users exist in more than one LDAP Group</title><link>https://support.levelblue.com/kb/Goto14436.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What if the same user exists in 2 or more LDAP groups and each LDAP group has different policies applied, what policy will be applied to the user?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;If an LDAP user is included in more than one group, the policy implemented will automatically be that of the first group appearing in the list. Group priority is listed from top to bottom.&lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Sun, 24 Nov 2013 03:52:40 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>How to configure ISA server in order to forward client IPs for HTTPS traffic as well</title><link>https://support.levelblue.com/kb/Goto13612.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;br /&gt;In an ISA-Finjan-Internet topology, with the Vital Security ISA Connector properly working with HTTP requests, no client IP addresses are forwarded to the Finjan appliance for HTTPS traffic.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;strong&gt;Symptoms&lt;/strong&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;br /&gt;The option "&lt;span style="font-size: 11pt; font-family: 'calibri','sans-serif';"&gt;Add headers to HTTPS CONNECT request" is not selected.&lt;/span&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;br /&gt;In ISA Server Management, select the Finjan ISA plugin. In the section "Configuration / Add-ins", mark the option as checked.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="width: 670px; overflow-x: scroll;"&gt;&lt;img alt="" style="border-width: 0px; border-style: solid;" src="https://support.levelblue.com/kb/attachments/images/992~ISA_https_forwd_1.jpg" /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;img alt="" style="border-width: 0px; border-style: solid;" src="https://support.levelblue.com/kb/attachments/images/993~ISA_https_forwd_2.jpg" /&gt;&lt;/div&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;strong&gt;Software Version&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #354b76;"&gt;&lt;a class="ApplyClass" href="ftp://Outgoing:Mr8om21r@swgftp.trustwave.com/support/ISA-FF/2004-2006/build%202.1.1/Setup.exe" target="_blank"&gt;Vital Security IP/Username Forwarding Plug-in for ISA Server 2004 to Vital Security IP/Username Forwarding Plug-in for ISA Server 2004 and ISA Server 2006&lt;/a&gt;&lt;br /&gt;v 2.1&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;dl style="margin-top: 10px;"&gt;    &lt;dt&gt;&lt;em&gt;This article applies to:&lt;/em&gt;&lt;/dt&gt;    &lt;dd&gt;&lt;em&gt;NG 1000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 5000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 6000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 8000&lt;/em&gt;&lt;/dd&gt;    &lt;em&gt;    &lt;/em&gt;&lt;/dl&gt;    &lt;em&gt;    &lt;dl style="margin-top: 10px;"&gt;        &lt;dt&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt;        &lt;/dt&gt;        &lt;dd&gt;&lt;em&gt;Finjan KB 1887&lt;/em&gt;        &lt;/dd&gt;    &lt;/dl&gt;    &lt;/em&gt;</description><pubDate>Fri, 23 Aug 2013 04:48:56 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>How To Exclude Web Applications From the Authentication Mechanism</title><link>https://support.levelblue.com/kb/Goto13553.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;br /&gt;Some web applications (such as Citrix Webmeeting) get stuck due to authentication requests which can not be handled by such applications.&lt;br /&gt;This article describes how to exclude them from authentication mechanism.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;strong&gt;Symptoms&lt;/strong&gt;&lt;br /&gt;Example:&lt;br /&gt;Citrix Webmeeting gets stuck, or the connection setup wizard does not succeed.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;br /&gt;An authentication request is sent to the client in a later session stage, but the application cannot handle it correctly.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;br /&gt;The solution is to exclude this application / site from authentication mechanism.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Drawback:&lt;/strong&gt; The client is not authenticated or identified anymore and the policy for unknown users is applied.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. Step:&lt;/strong&gt; Create a list of URLs you want to exclude (It might be necessary to do a packet trace and analyze the destination URLs)&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/929~add_url-list.jpg" style="border-width: 0px; border-style: solid; " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Step:&lt;/strong&gt; add a condition to your authentication policy (it might be different from this example):&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/930~add_condition_1.jpg" style="border-width: 0px; border-style: solid; " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/931~add_condition_2.jpg" style="border-width: 0px; border-style: solid; " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Note:&lt;/strong&gt; This condition is based on URLs, basically other conditions such as header fields are also possible - it depends on the needs.&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/932~add_condition_3.jpg" style="border-width: 0px; border-style: solid; " /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Step 3:&lt;/strong&gt; Commit your changes&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Note:&lt;/strong&gt; This option applies also to other identification policies (IP, Basic)&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;strong&gt;Software Version&lt;/strong&gt;&lt;br /&gt;9.x&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;dl style="margin-top: 10px; "&gt;    &lt;dt&gt;&lt;em&gt;This article applies to:&lt;/em&gt;&lt;/dt&gt;    &lt;dd&gt;&lt;em&gt;NG 1000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 5000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 6000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 8000&lt;/em&gt;&lt;/dd&gt;    &lt;em&gt;    &lt;/em&gt;&lt;/dl&gt;    &lt;em&gt;    &lt;dl style="margin-top: 10px; "&gt;        &lt;dt&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt;        &lt;/dt&gt;        &lt;dd&gt;&lt;em&gt;Finjan KB 1810&lt;/em&gt;        &lt;/dd&gt;    &lt;/dl&gt;    &lt;/em&gt;</description><pubDate>Fri, 31 Aug 2012 07:06:10 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Transparent authentication on SWG and virtual authentication hostname </title><link>https://support.levelblue.com/kb/Goto14915.aspx</link><description>&lt;h2 style="line-height: 18px; "&gt;&lt;/h2&gt;&lt;h2 style="line-height: 18px; "&gt;This article applies to:&lt;/h2&gt;&lt;ul style="line-height: 18px; "&gt;    &lt;li&gt;SWG 9.x deployed in transparent mode&lt;/li&gt;    &lt;li&gt;SWG 10.x    &lt;span style="font-size: 11px; line-height: 12px; "&gt;deployed in transparent mode&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 style="line-height: 18px; "&gt;Question:&lt;/h2&gt;&lt;ul style="line-height: 18px; "&gt;    &lt;li&gt;What is the purpose of virtual redirection hostname ?&lt;/li&gt;&lt;/ul&gt;&lt;h2 style="line-height: 18px; "&gt;Information:&lt;/h2&gt;&lt;p&gt;When SWG is deployed transparently, it can't authenticate clients using the "HTTP 407 Proxy Authentication" method that it uses in explicit mode.&lt;span style="white-space: pre; "&gt;&lt;/span&gt;Rather, it must use the same type of response that a web server would send "HTTP 401 Unauthorized".&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px; "&gt;In order to facilitate this, SWG redirects the traffic to a "virtual authentication hostname".&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 11px; line-height: 18px; "&gt;The virtual authentication hostname must resolve to an external IP so that SWG will have a chance to intercept the traffic and issue an authentication challenge.&lt;/span&gt;&lt;/p&gt;&lt;div style="font-size: 11px; line-height: 12px; "&gt;&lt;span style="line-height: 18px; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-size: 11px; line-height: 12px; "&gt;&lt;span style="line-height: 18px; "&gt;&lt;div style="font-size: 11px; line-height: 12px; "&gt;When the end-user sends the request to the Scanning Server and the &lt;span style="line-height: 18px; "&gt;Scanning Server is configured to perform user authentication, the S&lt;/span&gt;&lt;span style="font-size: 11px; line-height: 12px; "&gt;canning Server responds with an HTTP 302 Redirect, which redirects the &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;user to a virtual host. The virtual host is pre-configured, and its default &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;value is vhost.finjan.com. &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;The virtual host does not have to be a real host; &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;however, the host name of the virtual host must be resolvable by the enduser.&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br class="Apple-interchange-newline" /&gt;&lt;div&gt;&lt;span style="line-height: 18px; "&gt;&lt;div style="width: 700px; overflow: auto; "&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/14915/gui.jpg" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span&gt;&lt;div style="font-size: 11px; line-height: 12px; "&gt;&lt;div style="width: 700px; overflow: auto; "&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/14915/dump_01.png" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="font-size: 11px; line-height: 12px; "&gt;&lt;span class="Apple-tab-span" style="font-size: 11px; white-space: pre; "&gt;	&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 18px; "&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="font-size: 11px; line-height: 12px; "&gt;&lt;span style="line-height: 18px; "&gt;The end-user then closes the session and opens a new session for &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;the virtual host (which does not actually exist). When Vital Security &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;identifies a request for the virtual host, i&lt;/span&gt;&lt;span style="line-height: 18px; "&gt;t knows that it must perform user &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;authentication, and it responds to the end-user with HTTP 401 – &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;Authentication Required. &lt;/span&gt;&lt;/div&gt;&lt;div style="font-size: 11px; line-height: 12px; "&gt;&lt;span style="line-height: 18px; "&gt;The end-user then sends the credentials, and &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;the Scanning Server authenticates the end-user against the Active &lt;/span&gt;&lt;span style="line-height: 18px; "&gt;Directory.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;br class="Apple-interchange-newline" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span&gt;&lt;div style="width: 700px; overflow: auto; "&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/14915/dump_02.png" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 18px; white-space: pre; " class="Apple-tab-span"&gt;	&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 18px; "&gt;It is recommended to change the virtual &lt;/span&gt;&lt;span style="line-height: 18px; font-size: 11px; "&gt;authentication hostname to vhost (without ".finjan.com") and hosting the DNS entry for vhost on local DNS servers.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 18px; "&gt;For testing/evaluation purposes we have been using public DNS server addresses, i.g. 8.8.8.8 or 8.8.4.4. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;</description><pubDate>Fri, 10 Aug 2012 05:29:56 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>In transparent mode, user not authenticated/identified on HTTPS website</title><link>https://support.levelblue.com/kb/Goto14385.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;When a user browses a HTTP site, authentication/identification  works correctly and any subsequent HTTPS session works fine (the user is already authenticated/identified). When a user browses a HTTPS site first, authentication/identification doesn't work and the logs indicate the user is an "Unknown User". How can we correctly identify the user in both cases? (Configuration is Transparent mode, authenticate or get user credentials identification policy, and IP Caching is set as the "Authentication Retention Method").&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;    &lt;li&gt;A user opening a new browser to a HTTPS site is unrecognized (Unknown User), but there is no problem if the user first browses to a plain HTTP site and then any HTTPS site. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;Authenticate or Get User Credentials policy for HTTPS is not supported. This can be seen when trying to enable transparent mode on a device with the "Authenticate" or "Get User Credentials" identification policy, as the following alert is displayed:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span style="font-family: 'courier new'; "&gt;HTTPS Transaction will not be authenticated as long as Transparent Proxy is enabled.&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Or:&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/14385/warning.png" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;It works when HTTP is used first because the user credentials are cached after authentication, and are sent by the browser in subsequent requests to the SWG.&lt;/p&gt;</description><pubDate>Fri, 08 Jun 2012 06:34:06 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Windows 7 end users cannot authenticate with NTLM</title><link>https://support.levelblue.com/kb/Goto14592.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt; Client can connect with an XP workstation, but not with Windows 7&lt;/li&gt;    &lt;li&gt;Using 2008 AD server&lt;/li&gt;    &lt;li&gt;Client connections return a "STATUS_INVALID_PARAM" error code when you use a "Send NTLMv2 response only" authentication level in Windows Server&lt;br /&gt;    2008 or in Windows Vista&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Causes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;An issue in AD server&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;MS Solution to implement on the AD server is in:&lt;/p&gt;&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/957441" target="_blank"&gt;http://support.microsoft.com/kb/957441&lt;/a&gt; &lt;/p&gt;</description><pubDate>Thu, 24 May 2012 01:45:52 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>How to bypass Authentication by URL</title><link>https://support.levelblue.com/kb/Goto14451.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x&lt;/li&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;There may be a need to bypass Authentication for some sites. The below step by step will show how to setup an Authentication bypass list by URL. With this setup you will be able to add URL’s to a custom URL list that will bypass authentication for all users. &lt;br /&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;First, you will need to create a custom URL list that you can add sites too specifically for authentication bypass. To do this, go to Policies -&amp;gt; Condition Settings -&amp;gt; URL Lists. Add a new URL list; you can call this "Authentication Bypass List" (or any other name you want). Add the URL that you wish to bypass. &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/JB/12-30-20011/HowtobypassauthenticationbyulrURLLIST1.png" /&gt;&lt;/p&gt;&lt;p&gt;Second you will need to add a rule to the Identification rule you are using. Go to Policies -&amp;gt; Identification. Open the Identification Policy you are using and right click on the first rule. Click “add condition”. Condition name: URL list. Applies to: Everything except for the items selected below. And then select the new URL list you created in the first step. Save; commit&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/JB/12-30-20011/HowtobypassauthenticationbyulrIDENrule2.png" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;All users that are not authenticated will receive the Unknown Users Policy. &lt;/p&gt;</description><pubDate>Wed, 16 May 2012 14:07:33 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Authentication failure withMS AD 2008 R2 when using windows 7/vista Client</title><link>https://support.levelblue.com/kb/Goto14542.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;    &lt;li&gt;Windows Vista or Windows 7 clients &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Trying to configure authentication against Microsoft AD 2008 R2. &lt;/li&gt;    &lt;li&gt;With Windows XP clients, authentication is successful when you disable NTLM V2 enforcement. &lt;/li&gt;    &lt;li&gt;However with Windows 7 or Windows Vista c&lt;span id="result_box" lang="en" class="hps"&gt;lients&lt;/span&gt;, you see "Authentication failure" in the weblog viewer. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Causes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;This problem occurs because of an additional security check in Windows Server 2008 and Windows Vista. &lt;/li&gt;    &lt;li&gt;This problem is limited to clients that use NTLMv2 authentication without extended security. &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;To resolve this issue , you can install and configure a Hotfix that Microsoft provides for this issue. See the following Microsoft Knowledge Base article:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;a href="http://support.microsoft.com/kb/957441" class="ApplyClass" target="_blank"&gt;http://support.microsoft.com/kb/957441&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Mon, 14 May 2012 02:17:31 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>What is the policy assignment order?</title><link>https://support.levelblue.com/kb/Goto13373.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;strong&gt;Question&lt;/strong&gt;&lt;br /&gt;What is the policy assignment order for a User Group/User in Trustwave Secure Web Gateway appliance? &lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;strong&gt;Answer&lt;/strong&gt;&lt;br /&gt;&lt;p&gt;The policy assignment in Trustwave Secure Web Gateway appliance is as follows:&lt;/p&gt;&lt;/li&gt;&lt;/div&gt;&lt;ol&gt;    &lt;li&gt;The Local Users are being evaluated according to their respective username IP address. Please note that the Local Users are referred to as Independent Users in version 9.x/10.x. &lt;/li&gt;    &lt;li&gt;The Local Groups are being evaluated according to their set IP range. &lt;/li&gt;    &lt;li&gt;The imported LDAP users, which are associated with their relevant LDAP groups are then evaluated. &lt;/li&gt;    &lt;li&gt;The Unknown LDAP Users is then used, which may result due to unknown user which was imported to the SWG appliance as part of the LDAP objects, but is currently not associated with an LDAP group. &lt;/li&gt;    &lt;li&gt;Lastly, if all the above are not relevant, the Unknown Users group is then used, which means users that are completely unrecognized by the system. &lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;strong&gt;Software Version&lt;/strong&gt;&lt;br /&gt;9.x.x&lt;br /&gt;10.x &lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;dl style="margin-top: 10px; "&gt;    &lt;dt&gt;&lt;em&gt;This article applies to:&lt;/em&gt; &lt;/dt&gt;    &lt;dd&gt;&lt;em&gt;SWG 3000&lt;/em&gt; &lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;SWG 5000&lt;/em&gt; &lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;SWG 7000&lt;br /&gt;    &lt;/em&gt;&lt;em&gt;    &lt;/em&gt;&lt;/dd&gt;    &lt;dt&gt;&lt;em&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt; &lt;/em&gt;&lt;/dt&gt;    &lt;em&gt;    &lt;dd&gt;&lt;em&gt;Finjan KB 1521&lt;/em&gt; &lt;/dd&gt;    &lt;/em&gt;&lt;/dl&gt;</description><pubDate>Fri, 27 Apr 2012 00:41:00 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Allowing Office to retrieve content from Microsoft via SWG</title><link>https://support.levelblue.com/kb/Goto13844.aspx</link><description>&lt;P&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR&gt;An Identification Policy exception might be necessary on Secure Web Gateway (SWG) appliances in order to enable Office to download supplemental content from Microsoft.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Symptoms:&lt;/STRONG&gt;&lt;BR&gt;Although some clipart and templates are included with Office, much more is available as part of Microsoft’s online web collections.  Users might find that they are unable to access this online content from within Office applications.  When the administrator reviews the Web Log details that are related to these transactions, the following Identification Status is sometimes observed on the Policy Enforcement tab:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Error during authentication handshake&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Cause:&lt;/STRONG&gt;&lt;BR&gt;Some Office installations have restrictions on proxy authentication.  For example, most Office 2003 installations will not authenticate when a proxy is deployed transparently (including WCCP installations).  This can prevent users from being able to retrieve supplemental Microsoft Office content.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Solution:&lt;/STRONG&gt;&lt;BR&gt;If users are unable to download supplemental Office content from Microsoft, please follow the steps below to add an exception to the SWG appliance’s Identification Policy.  This procedure will work for built-in and custom Identification Policies in which the Exclude by Headers list serves as an exception condition.  If using a custom Identification Policy that does not utilize this Header Fields list, please add it as a condition to the rule that performs authentication and select “Everything except for the items selected below” in the Applies to field.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Navigate to &lt;STRONG&gt;Policies&lt;/STRONG&gt; -&amp;gt; &lt;STRONG&gt;Condition Settings&lt;/STRONG&gt; -&amp;gt; &lt;STRONG&gt;Header Fields&lt;/STRONG&gt;.&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;Select the &lt;STRONG&gt;Exclude by Headers&lt;/STRONG&gt; list.&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;Click the &lt;STRONG&gt;Edit&lt;/STRONG&gt; button.&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;Click the green &lt;STRONG&gt;+&lt;/STRONG&gt; button to add a new list entry.&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;In the &lt;STRONG&gt;Header Name&lt;/STRONG&gt; field, type:&lt;BR&gt;&lt;BR&gt;&lt;FONT face="Courier New"&gt;Host&lt;/FONT&gt;&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;In the &lt;STRONG&gt;Condition&lt;/STRONG&gt; field, select &lt;STRONG&gt;Regular Expression&lt;/STRONG&gt;.&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;In the &lt;STRONG&gt;Header Value&lt;/STRONG&gt; field, type:&lt;BR&gt;&lt;BR&gt;&lt;FONT face="Courier New"&gt;.*office(images)?.microsoft.com&lt;/FONT&gt;&lt;BR&gt;&lt;BR&gt;The entry should appear as it does in the screenshot below:&lt;BR&gt;&lt;BR&gt;&lt;IMG hspace=0 src="https://support.levelblue.com/kb/Attachments/eaccbb3f-41cd-4be3-89d0-14dc.png" border=0&gt;&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;Click the &lt;STRONG&gt;Save&lt;/STRONG&gt; button.&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Commit&lt;/STRONG&gt; the changes.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Please give the system ample time to finish committing before testing the change.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Software Versions:&lt;/STRONG&gt;&lt;BR&gt;9.x&lt;/P&gt;</description><pubDate>Wed, 16 Jun 2010 12:28:00 GMT</pubDate><dc:creator>Eric Hanson</dc:creator></item><item><title>Active Directory LDAP Username must be fully qualified in VSOS 9.2</title><link>https://support.levelblue.com/kb/Goto13605.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;Certain Active Directory LDAP settings that worked previously in VSOS 9.0, may require adjustment in VSOS 9.2. &lt;FONT color=#3366ff&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;BR&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;&lt;P&gt;When trying to import an Active Directory server, the import fails and displays an error message even though all fields are completed with the correct information. &lt;BR&gt;&lt;BR&gt;The following error message is displayed:&lt;BR&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" src="https://support.levelblue.com/kb/attachments/images/991~ad message.jpg" border=0&gt;&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;&lt;P&gt;A change in VSOS 9.2 allows user names to be input in different formats. &lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;&lt;P&gt;Because of this change, all user names are required to be input in a fully qualified format.     &lt;BR&gt;&lt;U&gt;&lt;BR&gt;For example:&lt;BR&gt;&lt;/U&gt;&lt;BR&gt;User@Domain.com &lt;BR&gt;Domain\User&lt;BR&gt;cn=user,cn=users,dc=domain,dc=com&lt;BR&gt;&lt;BR&gt;&lt;EM&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;Note: The user name format must be accepted by the Active Directory server.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;VSOS 9.2&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1879&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Wed, 01 Apr 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Multiple Administrators - Technical Brief</title><link>https://support.levelblue.com/kb/Goto13270.aspx</link><description>&lt;IFRAME src="https://support.levelblue.com/kb/attachments/1388.pdf" width=670 height=800&gt;&lt;/IFRAME&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1388&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Using Transparent Authentication Mechanism with FireFox</title><link>https://support.levelblue.com/kb/Goto13272.aspx</link><description>&lt;div class="atb54"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;As a result of the new Transparent Authentication mechanism added in Vital Security software version 8.4.3, the browser allows the end-user to connect to the internet &lt;U&gt;without sending requests for authentication&lt;/U&gt; from the end-user.&lt;BR&gt;&lt;BR&gt;This authentication request arrives from the browser as a result of the HTTP 401 Unauthorized Response sent from the web-server. &lt;BR&gt;&lt;BR&gt;If the authentication domain is resolvable as a hostname inside the orginization, the &lt;STRONG&gt;IE&lt;/STRONG&gt; browser will forward authentication details automatically. &lt;BR&gt;However, the &lt;STRONG&gt;FireFox &lt;/STRONG&gt;browser &lt;U&gt;will not do it automatically&lt;/U&gt;.&lt;BR&gt;&lt;BR&gt;How can we enable this automatic option  for FireFox  so that it does not send repeated requests for authentication to the end-user?&lt;/div&gt;&lt;br&gt;&lt;div class="atb55"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;In order to enable this automatic option for the FireFox browser, please do the following:&lt;OL&gt;&lt;LI&gt;Open FireFox browser.&lt;LI&gt;Type &lt;STRONG&gt;about:config&lt;/STRONG&gt; in the FireFox address bar.&lt;LI&gt;Select &lt;STRONG&gt;network.automatic-ntlm-auth.trusted-uris&lt;/STRONG&gt; in the Filter bar.&lt;LI&gt;Type in the virtual redirection hostname that you have defined for your Finjan appliance (e.g. vhost in the example below):&lt;BR&gt;&lt;BR&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/489~trans_auth232.jpg" border=0&gt;&lt;/div&gt;&lt;LI&gt;&lt;DIV align=left&gt;Virtual Redirection Hostname must be defined exactly as it is set for Finjan appliance: &lt;BR&gt;&lt;BR&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/488~trans_auth.jpg" border=0&gt;&lt;/div&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb56"&gt;&lt;li&gt;&lt;b&gt;VSOS&lt;/b&gt;&lt;br&gt;8.4.3&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1390&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>What are the supported configurations of an Authentication Device?</title><link>https://support.levelblue.com/kb/Goto13427.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;When configuring an authentication device with the Vital Security Web Appliance, what are the supported configurations of an authentication device?&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;The supported configurations are the following:&lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.5.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1590&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>How to install and configure ISA IP forwarding plug-in</title><link>https://support.levelblue.com/kb/Goto13203.aspx</link><description>&lt;IFRAME src="https://support.levelblue.com/kb/attachments/1282.pdf" width=670 height=800&gt;&lt;/IFRAME&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1282&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>SSL Authentication while using NG-5100 as a Next Proxy Server</title><link>https://support.levelblue.com/kb/Goto13194.aspx</link><description>&lt;div class="atb17"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;When using an NG-5100 appliance as a next proxy for the NG-5400 SSL appliance, and using NTLM authentication on the NG-5100, all SSL traffic fails.&lt;/div&gt;&lt;br&gt;&lt;div class="atb18"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;The SSL traffic fails when the NG-5400 is configured as next proxy to the NG-5100. When the NG-5400 routes directly to the internet (and not through NG-5100 as next proxy) the SSL traffic works correctly. &lt;/div&gt;&lt;br&gt;&lt;div class="atb19"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;The NG-5100 tries to authenticate every session which passes through it. However, since the NG-5400 has no credentials to authenticate with which are compliant with NTLM authentication, the session fails and an error message is displayed to the user.&lt;/div&gt;&lt;br&gt;&lt;div class="atb20"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;While using authentication, an NG-5400 SSL appliance, as well as the NG-5100 appliance, MUST have direct access to the Internet.&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1268&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Can a Lotus Notes client identify Windows Active Directory users, using Vital Security NG (NTLM authentication)?</title><link>https://support.levelblue.com/kb/Goto13188.aspx</link><description>&lt;div class="atb35"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;Can a Lotus Notes client identify Windows Active Directory users using Vital Security NG (NTLM authentication)?&lt;/div&gt;&lt;br&gt;&lt;div class="atb36"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;No, Lotus Notes does not support NTLM authentication.&lt;BR&gt;Therefore it can't authenticate Active Directory users that were imported by the Vital Security NG proxy, using NTLM authentication.&lt;BR&gt;&lt;BR&gt;There is an open feature request for IBM to add NTLM support to Lotus Notes.&lt;BR&gt;Please refer to the following link for more information: &lt;BR&gt;&lt;A title=http://www-1.ibm.com/support/docview.wss?rs=474&amp;uid=swg21190929 href="http://www-1.ibm.com/support/docview.wss?rs=474&amp;uid=swg21190929"&gt;&lt;FONT face=Arial size=2&gt;http://www-1.ibm.com/support/docview.wss?rs=474&amp;uid=swg21190929&lt;/FONT&gt;&lt;/A&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;BR&gt;&lt;BR&gt;&lt;LI&gt;&lt;STRONG&gt;Software Version&lt;BR&gt;&lt;/STRONG&gt;8.3.0&lt;BR&gt;8.3.5&lt;BR&gt;8.4.0&lt;BR&gt;8.4.3&lt;BR&gt;8.5.0&lt;/LI&gt;&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1260&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Read Headers identification method description and usage</title><link>https://support.levelblue.com/kb/Goto13544.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;&lt;P&gt;The Vital Security Web Appliance uses four different methods to identify and authenticate network users before allowing any web transaction:&lt;/P&gt;&lt;P&gt;1. Source IP.&lt;BR&gt;2. Read Headers.&lt;BR&gt;3. Get User Credentials.&lt;BR&gt;4. Authentication.&lt;/P&gt;&lt;P&gt;This article describes and demonstrates the Read Headers method.&lt;/P&gt;The "Read Headers" method was meant to be implemented in a topology which includes an additional proxy device that authenticates users on the network, such as a Microsoft ISA server, which is used as an example in the following scenario.&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;&lt;P&gt;In the "Read Headers" identification method, the Vital Security Web Appliance relies on the downstream proxy to provide headers information in each transaction. &lt;BR&gt;These headers would be used then to identify the username of the person who originated the transaction and/or the IP of the client machine from which the transaction originated. &lt;BR&gt;The Vital Security Web Appliance can be configured to monitor specific headers, such as X-Authenticated-User for username and/or X-Client-IP for client IP address information. In this scenario, it is assumed that the information forwarded by the downstream proxy is valid.&lt;BR&gt;The Vital Security Web Appliance does not attempt to verify the supplied data.&lt;/P&gt;&lt;P&gt;Please note that the Microsoft ISA server must be properly configured to forward this information to the Vital Security Web Appliance. &lt;BR&gt;Vital Security IP forwarding plugin should be installed on the Micrsoft ISA server for this purpose (please review the below Finjan Vital Knowledge Base article on this topic: &lt;A href="http://kb.finjan.com/article.asp?article=1282&amp;p=4"&gt;http://kb.finjan.com/article.asp?article=1282&amp;p=4&lt;/A&gt; ).&lt;/P&gt;&lt;P&gt;The plugin setup file can be downloaded from the below location:&lt;BR&gt;&lt;A href="http://download.finjan.com/products/ng/ipfwd/index.htm"&gt;http://download.finjan.com/products/ng/ipfwd/index.htm&lt;/A&gt;&lt;/P&gt;See the below image to confirm that Vital Security ISA connector is configured properly to forward the necessary information through HTTP headers of each transaction:&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/909~ISA Add-ins.jpg" border=0&gt;&lt;/div&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;The Vital Security Web Appliance should be then configured to use "Read Headers" identification policy: &lt;P&gt;This policy is designed to use one rule "Always Identify Users by Headers" :&lt;/P&gt;&lt;P&gt;This rule is set to "Identify by headers" action based on specific headers information:&lt;/P&gt;The headers to be used by this rule are predefined in the below "Pre Authenticated Headers" list: &lt;P&gt;As mentioned above, assuming that the information (IP / username) forwarded by the downstream proxy is valid, it then would be properly logged for further usage in reports / log viewer.&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.5.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1798&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>Amir Foox</dc:creator></item><item><title>Using authentication retention in terminal server environments</title><link>https://support.levelblue.com/kb/Goto13526.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;Can authentication retention be used in an environment with terminal servers?&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Definitions&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Authentication Rentention&lt;/STRONG&gt; mechanisms allow a Vital Security Appliance to temporarily cache a user's name. This means that the user does not need to reauthenticate with each transaction, thereby improving performance.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Terminal servers&lt;/STRONG&gt; are powerful computers that host multiple interactive sessions from different users simultaneously. Many organizations use Windows-based terminal server solutions, such as Microsoft's Terminal Services and similar offerings from Citrix. With these solutions, several users can simultaneously run individual Windows sessions on the same server. The applications within these sessions run on the server itself, rather than on the user's own client PC.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Answer Explanation&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It is possible to use the &lt;STRONG&gt;Cookie&lt;/STRONG&gt; authentication retention mechanism in terminal server environments. This method sends a temporary identification cookie to the browser, which works well on a multi-session system because cookies are not shared between sessions from different users.&lt;/P&gt;The &lt;STRONG&gt;IP Caching&lt;/STRONG&gt; authentication retention mechanism should not be used in terminal server environments. This method temporarily associates usernames with client IP addresses. In a terminal server environment, all transactions that originate from the terminal server will have the same client IP address. Since the terminal server can simultaneously host sessions from different users, a request from the IP address of the terminal server could have been made by any of the users on that server. Therfore, it is not possible to associate a specific transaction with a specific user by simply recognizing that the request came from the terminal server's IP.&lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.4.3&lt;BR&gt;8.5.0&lt;BR&gt;9.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1763&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>Eric Hanson</dc:creator></item><item><title>HTTP Error 553 due to Authentication Failure</title><link>https://support.levelblue.com/kb/Goto13515.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;After a new installation of VSOS 9.0, all users cannot browse to the Internet.&lt;/div&gt;&lt;br&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;All users get HTTP Error 553 - Internal Server Error.&lt;BR&gt;In the log viewer of the Management Console, you can see that the transactions failed at the authentication handshake phase:&lt;BR&gt;&lt;BR&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/874~Auth Error.jpg" border=0&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;In self-authentication / self-redirection authentication method, the scanners perform the authentication in front of the external authentication server (usually AD server).&lt;BR&gt;&lt;BR&gt;In order to perform this kind of authentication, the scanners should be able to reach the external authentication server/s.&lt;BR&gt;However, usually the domain controllers of the external authentication server are written in their relative / host name format, not in their FQDN (Fully Qualified Domain Name).&lt;BR&gt;&lt;BR&gt;In case the organization's domain is not configured in the DNS settings of the Vital Security Web Appliance, the scanners will not be able to resolve the domain controller name, and the self-authentication will fail.&lt;BR&gt;&lt;BR&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/875~Auth Error2.jpg" border=0&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;Define the organization's domain name in the DNS settings via the limited shell &lt;OL&gt;&lt;LI&gt;Access via SSH to the limited shell of the policy server. &lt;LI&gt;Type config_network -&amp;gt; Y -&amp;gt; choose option 4 (DNS) -&amp;gt; 1 (Change Search) -&amp;gt;  Type your domain -&amp;gt; Q -&amp;gt; Y&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;div&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/877~Auth Error3.jpg" border=0&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;9.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1741&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Internal Server Error while Working with an Authentication Device</title><link>https://support.levelblue.com/kb/Goto13420.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;An Authentication Device is used to authenticate users against an Authentication Server. When using a distributed setup including an Authentication Device, sometimes errors are received.&lt;/div&gt;&lt;br&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;When an authentication redirect is requested via the same proxy that required the authentication you will receive the following error message:&lt;BR&gt;&lt;IMG alt="" src="https://support.levelblue.com/kb/attachments/images/811~766.jpg" border=0&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;The proxy client will not forward the Authentication Request to the Authentication Device since this authentication redirect is not authenticated either.&lt;/div&gt;&lt;br&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;Make sure that the client or an intermediate proxy will forward the authentication redirect to the authentication device directly. This authentication redirects should not be forwarded via the same Finjan Proxy that required the authentication and issued the redirect itself.&lt;/div&gt;&lt;br&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.5.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1582&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item></channel></rss>