﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>LevelBlue Knowledge Base » Knowledgebase » Legacy Products » Secure Web Gateway » GUI</title><generator>InstantKB.NET 2.0.6</generator><description>LevelBlue Knowledge Base</description><link>https://support.levelblue.com/kb/</link><webMaster>website@m86security.com</webMaster><lastBuildDate>Tue, 21 Apr 2026 19:38:25 GMT</lastBuildDate><ttl>20</ttl><item><title>SWG Management Console (GUI) requires IE Compatibility View settings</title><link>https://support.levelblue.com/kb/Goto20040.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;    &lt;li&gt;Microsoft Internet Explorer 11 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Administrators are not able to log in to SWG Management console (GUI) &lt;/li&gt;    &lt;li&gt;The SWG Management console (GUI) does not notify the user about incorrect username or password &lt;/li&gt;&lt;/ul&gt;In most cases the login page will look slightly different when using the IE browser. &lt;br /&gt;&lt;p&gt;Normally, the login box should be centered on the screen, but in IE it is as shown below:&lt;/p&gt;&lt;p&gt;&lt;img alt="" style="height: 314px; width: 575px;" src="https://support.levelblue.com/kb/Uploads/Images/SM/20040/IE_login_page.JPG" /&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;h2&gt;Causes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Newer versions of the Internet Explorer browser are designed to better support recent HTML standards. As a result some of the web components in the SWG UI may not work as in the older IE versions. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;ol&gt;    &lt;li&gt;Open the Internet Explorer browser, click &lt;strong&gt;Tools&lt;/strong&gt; on the menu bar, and then choose &lt;strong&gt;Compatibility View Settings&lt;/strong&gt;. &lt;/li&gt;    &lt;li&gt;Add the IP address or hostname of the SWG Server to the list of websites added to Compatibility View:&lt;img alt="" style="height: 437px; width: 575px;" src="https://support.levelblue.com/kb/Uploads/Images/SM/20040/IE_compatibility_view.JPG" /&gt; &lt;/li&gt;    &lt;li&gt;Close the Compatibility View Settings dialog and reload the SWG management console. Observe the correct positioning of the login box.&lt;img alt="" style="height: 431px; width: 575px;" src="https://support.levelblue.com/kb/Uploads/Images/SM/20040/IE_login_page_02.JPG" /&gt; &lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;Compatibility View helps make websites designed for older browsers look better when viewed in Internet Explorer. &lt;/p&gt;&lt;p&gt;If you choose to view a website in Compatibility View, as a convenience to you, Internet Explorer will remember this choice and use Compatibility View the next time you visit the site.&lt;/p&gt;</description><pubDate>Thu, 30 Oct 2014 19:57:10 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>Change the IP address for a Policy Server/All-In-One device</title><link>https://support.levelblue.com/kb/Goto19520.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x - Policy Server / All-In-One &lt;/li&gt;    &lt;li&gt;SWG 11.x - Policy Server / All-In-One &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I change the IP address for a Policy Server / All-In-One device? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;The change is performed in two stages:&lt;/p&gt;&lt;p&gt;1) The IP address is changed on the networking interface, using the relevant Limited Shell commands.&lt;/p&gt;&lt;p&gt;2) The IP address is changed in the SWG database by an update in the SWG GUI.&lt;/p&gt;&lt;p&gt;These stages are detailed in the following steps:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;1. Open the SSH connection to the SWG device using its current IP address, and run the &lt;strong&gt;config_network &lt;/strong&gt;command.&lt;/p&gt;&lt;p&gt;     &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/19520/01.PNG" /&gt;&lt;/p&gt;&lt;p&gt;2. Type '&lt;strong&gt;Y&lt;/strong&gt;' to view further options, and then type '&lt;strong&gt;2&lt;/strong&gt;' to view the interfaces currently defined in the system.&lt;/p&gt;&lt;p&gt;     &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/19520/02.PNG" /&gt; &lt;/p&gt;&lt;p&gt;3. Choose the option for the interface you want to change; in this case it is interface eth0. Type '&lt;strong&gt;1&lt;/strong&gt;'. &lt;/p&gt;&lt;p&gt;     &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/19520/03.PNG" /&gt;&lt;/p&gt;&lt;p&gt;4. Type '&lt;strong&gt;1&lt;/strong&gt;' to change the IP address. &lt;/p&gt;&lt;p&gt;     &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/19520/04.PNG" /&gt;&lt;/p&gt;&lt;p&gt;5. Type the new IP address; in this case it is 208.90.236.220/26. &lt;/p&gt;&lt;p&gt;     &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/19520/05.PNG" /&gt; &lt;/p&gt;&lt;p&gt;6. Review the new configuration details and type '&lt;strong&gt;Y&lt;/strong&gt;' to save it: &lt;/p&gt;&lt;p&gt;     &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/19520/07.PNG" /&gt;&lt;/p&gt;&lt;p&gt;7. With this change enabled you should expect the SSH connection to fail. Try to open a new SSH connection using the new IP address to make sure that the change worked.&lt;/p&gt;&lt;p&gt;Proceed with the update of the new IP address in the database, using the SWG GUI: &lt;/p&gt;&lt;p dir="ltr" style="margin-right: 0px;"&gt;&lt;strong&gt;Note:&lt;/strong&gt; The IP address change has been already performed at the networking level, so you should access the GUI using the new IP address.&lt;/p&gt;&lt;p dir="ltr"&gt;8. In the GUI, navigate to the &lt;strong&gt;SWG Devices&lt;/strong&gt; section and highlight the Policy Server device IP. &lt;/p&gt;&lt;p dir="ltr" style="margin-right: 0px;"&gt;The left pane should still show the old IP address.&lt;/p&gt;&lt;p&gt;9. Click &lt;strong&gt;Edit&lt;/strong&gt;, and make sure the Device IP in the right pane shows the new IP address.&lt;br /&gt;&lt;br /&gt;10. Save and commit the changes.&lt;/p&gt;&lt;p&gt;     &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/19520/08.PNG" style="height: 513px; width: 575px;" /&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;br /&gt;</description><pubDate>Thu, 09 Oct 2014 11:58:48 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>Quickly rebuild an SWG Virtual Scanner</title><link>https://support.levelblue.com/kb/Goto16570.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What is the easiest way to recreate an SWG virtual scanner?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;1. Remove the virtual scanner from the list of scanners in the Policy Server GUI (right-click the scanner and choose &lt;strong&gt;Delete&lt;/strong&gt;).&lt;br /&gt;&lt;br /&gt;2. Download the scanner VMDK and OVF files from the Trustwave SWG download page: &lt;a class="ApplyClass" href="http:"&gt;https://support.levelblue.com/Secure-Web-Gateway/Upgrade.asp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3. Delete the scanner virtual machine from the VM environment.&lt;br /&gt;&lt;br /&gt;4.&lt;span style="background-color: #ffffff;"&gt; Create the new scanner VM by placing the OVF and VMDK files in the same folder, and then drag/drop the OVF into the VMware instance (or create the new VM and select the OVF file).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The Scanner should build itself and complete.&lt;br /&gt;&lt;br /&gt;5. Boot the new VM scanner and log in with the credentials: &lt;strong&gt;ad&lt;/strong&gt;&lt;span style="background-color: #ffffff;"&gt;&lt;strong&gt;min&lt;/strong&gt;/&lt;strong&gt;finjan &lt;/strong&gt;(For V11.5 and later the default password is &lt;strong&gt;TrustwaveSWG&lt;/strong&gt;).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;6. Run th&lt;span style="background-color: #ffffff;"&gt;e setup command an&lt;/span&gt;d provide networking information (this will probably be identical to the previous system that was deleted).&lt;br /&gt;&lt;br /&gt;7. Log into the Policy Server GUI and add the new VM scanner to the devices tree.&lt;/p&gt;&lt;p&gt;8. Click &lt;strong&gt;Save &lt;/strong&gt;and commit the changes.&lt;/p&gt;&lt;br /&gt;</description><pubDate>Tue, 11 Feb 2014 01:24:40 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Users exist in more than one LDAP Group</title><link>https://support.levelblue.com/kb/Goto14436.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What if the same user exists in 2 or more LDAP groups and each LDAP group has different policies applied, what policy will be applied to the user?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;If an LDAP user is included in more than one group, the policy implemented will automatically be that of the first group appearing in the list. Group priority is listed from top to bottom.&lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Sun, 24 Nov 2013 03:52:40 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Filter Entrapper block transactions in the Web Log</title><link>https://support.levelblue.com/kb/Goto16283.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Is there a filter option to show Entrapper blocks only?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;The Malware Entrapment engine, also known as Entrapper, was first introduced with SWG OS 10.1.&lt;/p&gt;&lt;p&gt;1. Go to &lt;strong&gt;Logs and Reports &amp;gt; Audit Logs&lt;/strong&gt;, right-click the selected view and choose &lt;strong&gt;View Settings&lt;/strong&gt;. &lt;/p&gt;&lt;p&gt;2. In the Filter tab, use the settings below to show only Entrapper blocks out of all the log transactions available in the system:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/16283/weblog_profile.PNG" style="width: 575px; height: 196px;" /&gt;&lt;br /&gt;This filter relies on the actual text of the user response action specified for this rule in your policy.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;Below is a snapshot of the default End User Message as defined in the Default Security Policy:&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/10267/BlockMalwareForKB.jpg" style="width: 600px; height: 226px;" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;And here is the snapshot of the actual text in the message:&lt;br /&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/10267/EntrapperForKB.jpg" style="width: 666px; height: 282px;" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If these settings are modified with custom settings make sure to update the suggested filter to reflect the custom settings.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</description><pubDate>Sun, 24 Nov 2013 01:52:52 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>502 Bad Gateway error – Squid is not running</title><link>https://support.levelblue.com/kb/Goto16471.aspx</link><description>&lt;p class="MsoNormal" style="line-height: normal;"&gt;&lt;strong&gt;&lt;span style="font-size: 12pt; font-family: 'trebuchet ms', sans-serif; color: #3c71a6;"&gt;INFO:502 Bad Gateway – Squid is not running.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="font-size: 11.111111640930176px; line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;strong&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;This article applies to:&lt;/span&gt;&lt;/strong&gt;&lt;strong&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 8pt; font-family: verdana, sans-serif;"&gt;SWG: 11.x&lt;/span&gt;&lt;span style="font-size: 12pt; font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size: 12pt; font-family: verdana, sans-serif;"&gt;  &lt;strong&gt;Description&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;&lt;br /&gt;In some scenarios Squid won’t start and in the GUI you may see a communication such as:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;"This cache server is not active."&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size: 12pt; font-family: verdana, sans-serif;"&gt;  &lt;strong&gt;Symptoms&lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt;You will see a 502 Bad Gateway error.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size: 12pt; font-family: verdana, sans-serif;"&gt;  &lt;strong&gt;Cause&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;&lt;br /&gt;It is a known bug in Squid that it does not accept some special chars like "_" or "-".&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;span style="line-height: normal; font-family: verdana, sans-serif;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="font-size: 12pt; font-family: symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size: 12pt; font-family: verdana, sans-serif;"&gt;  &lt;strong&gt;Solution&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: verdana, sans-serif;"&gt;&lt;br /&gt;Change the hostname to a name without special, reserved characters.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-size: 11pt; font-family: calibri, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-size: 11pt; font-family: calibri, sans-serif;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 0.0001pt;"&gt;&lt;strong&gt;&lt;span style="font-size: 18pt; font-family: verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 0.0001pt;"&gt;&lt;strong&gt;&lt;span style="font-size: 18pt; font-family: verdana, sans-serif;"&gt;Notes:&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size: 18pt; font-family: verdana, sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 0.0001pt;"&gt;&lt;strong&gt;&lt;span style="font-size: 18pt; font-family: verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-size: 8.5pt; font-family: verdana, sans-serif;"&gt;Changes like this will cause certain processes to restart on the SWG and may interrupt scanning in a production environment.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-size: 8.5pt; font-family: verdana, sans-serif;"&gt;It is recommended to do this during a maintenance window where it’s appropriate for the system to go down. &lt;/span&gt;&lt;span style="font-size: 8.5pt; font-family: verdana, sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 0.0001pt;"&gt;&lt;span style="font-size: 11pt; font-family: calibri, sans-serif;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;em&gt;&lt;span style="font-size: 8.5pt; line-height: 115%; font-family: verdana, sans-serif;"&gt;&lt;br /&gt;&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/em&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;</description><pubDate>Sun, 24 Nov 2013 01:48:51 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Video streaming contents from youtube.com are not working correctly when served through SWG</title><link>https://support.levelblue.com/kb/Goto15304.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What is the reason that the video streams from youtube.com are not loading properly when requested through SWG ?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This one appears to be a brand new ‘known’ issue that was reported by multiple customers during last few days.&lt;/p&gt;&lt;p&gt; &lt;span style="line-height: 12px;"&gt;Until recently video streams hosted on youtube.com were allowed through SWG by Allow Streaming rule (top rule in the policy).&lt;/span&gt;&lt;/p&gt;&lt;p&gt;This rule triggers allow action based on content types that we identify when known streaming contents are served to SWG.&lt;/p&gt;&lt;p&gt;Most likely, there were some changes in the way youtube servers share these streams today, and as a result we are not able to detect it any longer.&lt;/p&gt;&lt;p&gt;Since Allow Streaming rule does not take any action, the contents are sent for scanning through the policy. Status page is triggered as a result and it stalls just like it usually happens with status page. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;This issue has been reported internally, and we are expecting to get further instructions from our engineering team.&lt;/p&gt;&lt;p&gt;Before we know what exactly works different with youtube video streaming contents use the following work around to address the issue:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;add a new argument to the Unless tab not activate status page whenever Mime Type contains application/octet-stream &lt;/span&gt;&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;save and commit changes:&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/15304/2013-09-24_17h10_12.png" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;</description><pubDate>Mon, 07 Oct 2013 02:09:39 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>How to backup SWG</title><link>https://support.levelblue.com/kb/Goto16088.aspx</link><description>&lt;strong style="font-size: medium;"&gt;This article applies to:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 18px;"&gt;SWG 10.x&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 18px;"&gt;SWG 11.x&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size: 16px;"&gt;&lt;strong&gt;Question:&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;How do I create a backup of my SWG settings and configuration?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 16px;"&gt;&lt;strong&gt;Procedure:&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;There is a feature in SWG called "Backup" (or "Rollback" in SWG version 10.x.) This feature allows you to create a backup file of your SWG where it can be saved in an alternate location (backups are not saved locally on the SWG).  A backup consists of all data that an administrator can customize in the Management Console (including Policies, Settings etc.).&lt;br /&gt;&lt;br /&gt;To create a rollback:&lt;div&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;In SWG 10.x, navigate to &lt;/span&gt;&lt;strong style="font-size: 8pt;"&gt;Administration &amp;gt; Rollback &amp;gt; Rollback Settings&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;In SWG 11.x, navigate to &lt;/span&gt;&lt;strong style="font-size: 8pt;"&gt;Administration &amp;gt; Policy Server DB Backup &amp;gt; Backup Settings&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;From here you can configure a connection method location and scheduling for the backup. If you have any trouble in configuring the backup, click the "?" or &lt;strong&gt;F1&lt;/strong&gt; Help button to see additional information about backup settings.&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration: underline;"&gt;Why is backup helpful?&lt;/span&gt; In the event of a critical system failure where the SWG is not recoverable, the SWG system can be re-imaged to its default factory settings. After it has been reset to its factory settings, the last saved backup can be applied to the system restoring the custom configuration and settings.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 16px;"&gt;Note:&lt;/span&gt;&lt;br /&gt;System backups do not include information in the LogServer database, Reports Server database (see &lt;strong style="font-size: 8pt;"&gt;Administration &amp;gt; Reports DB Backup &amp;gt; Backup Settings&lt;/strong&gt;&lt;span style="font-size: 8pt;"&gt;)&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;, Custom Block Messages, and Updates.  &lt;/span&gt;&lt;/div&gt;</description><pubDate>Tue, 24 Sep 2013 08:31:31 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Malware Entrapment Profile levels as shown in the weblogs</title><link>https://support.levelblue.com/kb/Goto14490.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG v10.1 and above&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Malware Entrapment Profile level is set to Strict, however, transaction shows Basic, Medium and Strict levels. Why?&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 13px; font-size: 12px;"&gt;Malware Entrapment Profile is blocking too much/little content. Can I adjust it?&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;As of SWG 10.1, the User Interface allows adjustment of Malware Entrapment Profile (MEP) security level. To do this, highlight the Malware Entrapment Profile condition in the "Block Malicious Content (Malware Entrapment Engine)" Rule and set its level as desired in the right pane, as shown below:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14490/Malware%20Entrapment%20Profile.jpg" style="width: 600px; height: 260px;" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Web content will be blocked by MEP up to and including the specified threshold, e.g. if set to Medium, content is blocked if it breaks Basic or Medium. The transaction log will show what MEP level was reached, so if MEP is set to Strict the transaction logs will show Basic, Medium and Strict entries.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Note that if the Logging Policy is set to log more than Blocked/Corrective actions (e.g. "Log everything except images"), then the logs will show MEP levels for traffic that was not blocked, indicating that the Entrapper engine was called but allowed the traffic, as shown in green below:&lt;/p&gt;&lt;div&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/SM/14490/Malware%20Entrapment%20Profile%20-%20log.jpg" style="width: 600px; height: 285px;" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;None.</description><pubDate>Sun, 15 Sep 2013 01:17:30 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>How to configure ISA server in order to forward client IPs for HTTPS traffic as well</title><link>https://support.levelblue.com/kb/Goto13612.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;br /&gt;In an ISA-Finjan-Internet topology, with the Vital Security ISA Connector properly working with HTTP requests, no client IP addresses are forwarded to the Finjan appliance for HTTPS traffic.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;strong&gt;Symptoms&lt;/strong&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;br /&gt;The option "&lt;span style="font-size: 11pt; font-family: 'calibri','sans-serif';"&gt;Add headers to HTTPS CONNECT request" is not selected.&lt;/span&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;br /&gt;In ISA Server Management, select the Finjan ISA plugin. In the section "Configuration / Add-ins", mark the option as checked.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="width: 670px; overflow-x: scroll;"&gt;&lt;img alt="" style="border-width: 0px; border-style: solid;" src="https://support.levelblue.com/kb/attachments/images/992~ISA_https_forwd_1.jpg" /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;img alt="" style="border-width: 0px; border-style: solid;" src="https://support.levelblue.com/kb/attachments/images/993~ISA_https_forwd_2.jpg" /&gt;&lt;/div&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;strong&gt;Software Version&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #354b76;"&gt;&lt;a class="ApplyClass" href="ftp://Outgoing:Mr8om21r@swgftp.trustwave.com/support/ISA-FF/2004-2006/build%202.1.1/Setup.exe" target="_blank"&gt;Vital Security IP/Username Forwarding Plug-in for ISA Server 2004 to Vital Security IP/Username Forwarding Plug-in for ISA Server 2004 and ISA Server 2006&lt;/a&gt;&lt;br /&gt;v 2.1&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;dl style="margin-top: 10px;"&gt;    &lt;dt&gt;&lt;em&gt;This article applies to:&lt;/em&gt;&lt;/dt&gt;    &lt;dd&gt;&lt;em&gt;NG 1000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 5000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 6000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;NG 8000&lt;/em&gt;&lt;/dd&gt;    &lt;em&gt;    &lt;/em&gt;&lt;/dl&gt;    &lt;em&gt;    &lt;dl style="margin-top: 10px;"&gt;        &lt;dt&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt;        &lt;/dt&gt;        &lt;dd&gt;&lt;em&gt;Finjan KB 1887&lt;/em&gt;        &lt;/dd&gt;    &lt;/dl&gt;    &lt;/em&gt;</description><pubDate>Fri, 23 Aug 2013 04:48:56 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>What is the longest URL that could be added to the URL list?</title><link>https://support.levelblue.com/kb/Goto14914.aspx</link><description>&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;URL list entry - what is the limit on the URL length ?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;The following error message could show up when adding a very long URL:&lt;/p&gt;&lt;/div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/14914/error_msg.JPG" style="width: 600px; height: 391px;" /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;When adding a URL from the logs section, the error message would be different:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/14914/error_msg_02.jpg" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;Every URL list entry is a name stored in the DB being the same as the URL itself&lt;br /&gt;This name field in the DB is limited to 192 chars.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;If needed there are ways to extend this field manually, however, these changes are not recommended.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;Our recommendation for such URLs is to use a RegEx entry with a wildcard:  domain_name*file_name .&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</description><pubDate>Fri, 19 Jul 2013 01:31:38 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Customized messages for user response action are not retained with Version 11.0 upgrade</title><link>https://support.levelblue.com/kb/Goto15963.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Why do Block page messages look different after the system is upgraded to Version 11.0?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;div&gt;&lt;span style="line-height: 12px;"&gt;This is a known issue with the V11.0 upgrade - Rule Action messages are reset to default.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;To restore these messages, we recommend saving them before upgrading the system:&lt;br /&gt;&lt;br /&gt;1. Navigate to &lt;strong&gt;Policies &amp;gt;&lt;/strong&gt; &lt;strong&gt;End User Messages &lt;/strong&gt;&amp;gt; &lt;strong&gt;Message Template&lt;/strong&gt;, and select the relevant message template from the &lt;strong style="font-size: 8pt;"&gt;Rule Action &lt;/strong&gt;&lt;span style="line-height: 12px;"&gt;drop down list.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SWG/MessageTemplate.jpg" style="width: 600px; height: 310px;" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2. Click the &lt;strong&gt;Switch to HTML&lt;/strong&gt; &lt;strong&gt;View &lt;/strong&gt;button. The message is displayed &lt;span style="line-height: 12px;"&gt;in HTML&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;, similar to that shown below:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SWG/MessageTemplateHTMLonly.jpg" style="width: 600px; height: 172px;" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;3. Select the HTML code presented in this view, copy it and to paste it into a text file using the text editor of your choice.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;4. Save the file and click the &lt;strong&gt;Cancel &lt;/strong&gt;button in the SWG UI.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;5. Repeat these steps for the next Rule Action message details.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img alt="" style="width: 600px; height: 0px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/15963/html_view.PNG" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Once the SWG system is upgraded and running V11.0, follow the steps above to restore the HTML code for the custom messages used by SWG before the upgrade.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><pubDate>Mon, 08 Jul 2013 02:24:33 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>SWG URL List search mechanism is case-sensitive</title><link>https://support.levelblue.com/kb/Goto15237.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.0&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Is URL List search mechanism case-sensitive ?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;Starting &lt;span style="line-height: 18px;"&gt;with SWG 10.1 version administrator may run a quick search on URL entries to find out if a given URL is listed in any URL lists.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;It is also possible to run such search queries on a part of the domain name used for this URL. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;This search mechanism is case-sensitive, and below example demonstrates that.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 18px;"&gt;1. Create a new URL list with the following entries in it:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 18px;"&gt;TRUSTwave.com/*&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 18px;"&gt;TRUSTWAVE.com/*&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 18px;"&gt;www.trustwave.com/*&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/15237/01.png" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;2&lt;/span&gt;. Save and commit the changes, and proceed with the search feature by using right-click of the mouse on URL Lists node.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;3. Run search for TRUST keyword and see the results:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/15237/02.png" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;4. Run another search query, this time using 'trustwave' as keyword :&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/15237/03.png" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 18px;"&gt;The results are different, and this may affect the troubleshooting when trying to locate a specific URL entry.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 18px;"&gt;However, it does not affect the business logic, and the action (block or allow) will be taken correctly.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 18px;"&gt;This issue is consistent for all current SWG software versions.&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</description><pubDate>Sun, 17 Feb 2013 00:11:02 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Getting XMLHTTP support error message upon logging to SWG UI</title><link>https://support.levelblue.com/kb/Goto14824.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.1 or higher&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;User is getting below error message upon logging to SWG UI:&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/14824/XMLHTTP-error.jpg" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;h2&gt;Causes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;This issue was reported for IE browser(s) but may also be relevant for other browsers.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;p&gt;Make sure that the following Advanced Security option is enabled in IE browser:&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/14824/XMLHTTP-IE.jpg" /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;	&lt;/span&gt;&lt;/p&gt;</description><pubDate>Wed, 18 Jul 2012 06:11:13 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>How to Reset the Admin Password</title><link>https://support.levelblue.com/kb/Goto13206.aspx</link><description>&lt;div class="atb17"&gt;&lt;li&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;br /&gt;The administrator password in software version 8.x/9.x/10.x needs to be reset.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb18"&gt;&lt;li&gt;&lt;strong&gt;Symptoms&lt;/strong&gt;&lt;br /&gt;Unable to login to the Setup Console (webmin) or to the limited shell as an admin user.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb19"&gt;&lt;li&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;br /&gt;The admin password has been changed or forgotten.&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb20"&gt;&lt;li&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;br /&gt;In all supported software versions you can reset the admin password to the original password.&lt;br /&gt;To perform this action:&lt;ol&gt;    &lt;li&gt;Reboot the machine.  &lt;br /&gt;    On an NG-1000 or NG-5000, please use the shutdown option available by pressing the down arrow button on the LCD panel.  &lt;br /&gt;    After you have confirmed the shutdown twice by pressing the ENTER button on the LCD panel, please wait two minutes for the system to complete its soft shutdown prior to turning off the power switch on the back of the appliance.  &lt;br /&gt;    On an NG-6000/SWG-3000 appliance, press and release the white power button to initiate the shutdown.  &lt;br /&gt;    The unit will shut off when the soft shutdown is complete.  &lt;br /&gt;    On an NG-8000/SWG-7000 blade, the restart can be performed from the management module.    &lt;/li&gt;    &lt;li&gt;Connect a USB keyboard and VGA monitor to the unit, and turn the unit back on. &lt;br /&gt;    On an NG-8000/SWG-7000 blade, the management module's remote control feature can be used instead.    &lt;/li&gt;    &lt;li&gt;Before the operating system loads, you might see a repeating message, saying "Press any key to continue". &lt;br /&gt;    Press a key (such as the spacebar) while the message is still repeating.  &lt;br /&gt;    &lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/kernel_message_00.jpg" /&gt;&lt;br /&gt;    This will bring up the screen shown in the image below.  &lt;br /&gt;    If the "Press any key to continue" message does not  display, the screen shown in the photograph below should appear automatically.    &lt;/li&gt;    &lt;li&gt;Within a few seconds of the appearance of the screen shown below, use the down arrow key on your keyboard to highlight 'Reset Admin Password'.  Press the Enter key on your keyboard to select this option.  Doing so will reset the admin password to: &lt;strong&gt;finjan&lt;br /&gt;    &lt;img alt="" style="width: 539px; height: 298px; " src="https://support.levelblue.com/kb/Uploads/Images/13206_reset_admin_pw.jpg" /&gt; &lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div style="width: 670px; overflow-x: scroll; "&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/div&gt;&lt;strong&gt;&lt;/strong&gt;&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Software Version&lt;br /&gt;&lt;/strong&gt;8.x&lt;br /&gt;9.x&lt;br /&gt;10.x&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;dl style="margin-top: 10px; "&gt;    &lt;dt&gt;&lt;em&gt;This article applies to:&lt;/em&gt;&lt;/dt&gt;    &lt;em&gt;all appliances&lt;br /&gt;    &lt;/em&gt;&lt;/dl&gt;    &lt;dl style="margin-top: 10px; "&gt;        &lt;dt&gt;&lt;em&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt;        &lt;/em&gt;&lt;/dt&gt;        &lt;dd&gt;&lt;em&gt;&lt;em&gt;Finjan KB 1290&lt;/em&gt;        &lt;/em&gt;&lt;/dd&gt;    &lt;/dl&gt;</description><pubDate>Wed, 23 May 2012 07:19:51 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Supported web browsers for Admin GUI</title><link>https://support.levelblue.com/kb/Goto14486.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x &lt;/li&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What web browsers are supported for use with the SWG administration GUI? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Answer:&lt;/h2&gt;&lt;h3&gt;Officially supported:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Internet Explorer 7 (and higher) &lt;/li&gt;    &lt;li&gt;Firefox 1.5 (and higher) &lt;/li&gt;    &lt;li&gt;Chrome (all versions) &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Unofficially supported:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Safari (all versions) &lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Not supported:&lt;/h3&gt;&lt;ul&gt;    &lt;li&gt;Opera &lt;/li&gt;    &lt;li&gt;Any browsers not mentioned above&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;"Unofficially supported" browsers work for most functionality. Some customers have reported some issues with these browsers that have not been verified or reproduced. If a customer encounters problems accessing the GUI with these browsers, Trustwave does not provide assistance. Trustwave will ask the customer to use an officially supported browser. &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Mon, 14 May 2012 02:28:16 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>What is the "Used in" option for, in the Digital Certificate page</title><link>https://support.levelblue.com/kb/Goto14553.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What is the "Used in" right-click option in the Digital Certificate page for?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;It is not relevant in this page since there is no such Content Processor and it is not used in the policies. Ignore it.&lt;/p&gt;&lt;br /&gt;</description><pubDate>Mon, 23 Apr 2012 08:24:25 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Manipulating large URL lists</title><link>https://support.levelblue.com/kb/Goto14046.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x &lt;/li&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;    &lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;How do I manipulate large URL Lists? &lt;o:p&gt;&lt;/o:p&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p class="MsoNoSpacing"&gt;It is possible to export SWG's URL Lists to text files, modify them offline, and import them back into the the system.&lt;/p&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;To Export a URL List:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;    &lt;div class="MsoNoSpacing"&gt;Go to &lt;strong&gt;Policies&lt;/strong&gt; -&amp;gt; &lt;strong&gt;Condition settings&lt;/strong&gt; -&amp;gt; &lt;strong&gt;URL Lists&lt;/strong&gt;.&lt;br /&gt;    &lt;br /&gt;    &lt;span&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/URL%20Lists.jpg" /&gt;&lt;br /&gt;    &lt;/span&gt;&lt;/div&gt;    &lt;/li&gt;    &lt;li&gt;    &lt;div class="MsoNoSpacing"&gt;Click on the URL list that you wish to export. There are two ways to export the list to a file.&lt;br /&gt;     &lt;br /&gt;    &lt;/div&gt;    &lt;ul&gt;        &lt;li&gt;        &lt;div class="MsoNoSpacing"&gt;Right click the URL list you wish to export, and select &lt;strong&gt;Export to File&lt;/strong&gt;.&lt;br /&gt;        &lt;br /&gt;        &lt;span&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/Export%20File.jpg" /&gt;&lt;br /&gt;        &lt;/span&gt;&lt;/div&gt;        &lt;/li&gt;        &lt;li&gt;        &lt;div class="MsoNoSpacing"&gt;&lt;radeditorformatted_4 /&gt;With the URL list selected you wish to export, click the &lt;strong&gt;Export to File&lt;/strong&gt; button in the upper left side of the pane. &lt;span&gt;&lt;radeditorformatted_5 /&gt;&lt;/span&gt;&lt;/div&gt;        &lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNoSpacing"&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;To Import a URL List:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNoSpacing"&gt;Once you have altered the URL list, you can then import it back in by using either of the following two methods.&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;Right click the URL list and select &lt;strong&gt;Import to List&lt;/strong&gt;.&lt;br /&gt;     &lt;br /&gt;    &lt;span&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/Import%20List.jpg" /&gt;&lt;br /&gt;      &lt;/span&gt;&lt;/li&gt;    &lt;li&gt;After selecting the list into which you wish to import, click the &lt;strong&gt;Import to List&lt;/strong&gt; button in the upper left side of the pane. &lt;/li&gt;&lt;/ul&gt;</description><pubDate>Fri, 10 Jun 2011 18:26:15 GMT</pubDate><dc:creator>Eric Hanson</dc:creator></item><item><title>Rollback and FTP permissions</title><link>https://support.levelblue.com/kb/Goto13282.aspx</link><description>&lt;div class="atb54"&gt;&lt;li&gt;&lt;strong&gt;Question&lt;/strong&gt;&lt;br /&gt;Rollback is used to backup the Vital Security NG configurations to FTP/Samba server (network share folder).&lt;br /&gt;It's important to understand how the Rollback process operates for configuration and troubleshooting purposes.&lt;br /&gt;&lt;br /&gt;How does the Rollback mechanism operate and what are the needed FTP/Samba permissions for its successful operation?&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb55"&gt;&lt;li&gt;&lt;strong&gt;Answer&lt;/strong&gt;&lt;br /&gt;The Rollback operates in the following order (in this case Rollback is being configured for the first time and manual backup is performed):&lt;ol&gt;    &lt;li&gt;A file named “date” is being written to FTP/Samba folder, it contains date and time of its creation.    &lt;/li&gt;    &lt;li&gt;A file named “index.xml” is being written to FTP/Samba folder, it contains the string “&amp;lt;?xml version="1.0"?&amp;gt;”    &lt;/li&gt;    &lt;li&gt;A file named “backup_YYYY_MM_DD_HH_MM_SS.tar.enc” is being written to FTP/Samba folder, it contains the Vital Security appliance's configurations.    &lt;/li&gt;    &lt;li&gt;A file named “index.xml” that now contains the new created file record, is overwriting the old index.xml file.&lt;br /&gt;    Each backup file record inside the index.xml contains the following tags:&lt;br /&gt;    &amp;lt;&lt;strong&gt;file name&lt;/strong&gt;="backup_YYYY_MM_DD_HH_MM_SS.tar.enc"&amp;gt;&lt;br /&gt;    &amp;lt;&lt;strong&gt;creation_date&lt;/strong&gt; year="YYYY" month="MM" day="DD" hour="HH" minute="MM" second="SS" /&amp;gt;&lt;br /&gt;    &amp;lt;&lt;strong&gt;type&lt;/strong&gt; value="Manual or Scheduled"/&amp;gt;&lt;br /&gt;    &amp;lt;&lt;strong&gt;ng_version&lt;/strong&gt; value="8.x.x" /&amp;gt;&lt;br /&gt;    &amp;lt;&lt;strong&gt;description&lt;/strong&gt;&amp;gt;the description string&amp;lt;/description&amp;gt;&lt;br /&gt;    &lt;br /&gt;    &lt;div&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/13282_1.jpg" /&gt;&lt;br /&gt;    &lt;/div&gt;    &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Every time Administrator enters Rollback (after the FTP / Samba settings are entered and the administrator clicks on Apply and then on the &lt;strong&gt;Refresh&lt;/strong&gt; button), the system tries to read the index.xml file and to display the entries in it. These entries are the backup files that can be used to restore the previous configuration.&lt;br /&gt;&lt;/p&gt;&lt;div style="width: 670px; overflow-x: scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/13282_2.jpg" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Please note&lt;/strong&gt;, it is very important that the FTP server will allow permissions to  &lt;strong&gt;read&lt;/strong&gt;, &lt;strong&gt;write&lt;/strong&gt; and &lt;strong&gt;delete&lt;/strong&gt; files, &lt;span&gt;otherwise the Rollback will fail.&lt;/span&gt;&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb56"&gt;&lt;li&gt;&lt;strong&gt;VSOS&lt;/strong&gt;&lt;br /&gt;8.5&lt;br /&gt;9.x&lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;dl style="margin-top: 10px;"&gt;    &lt;dt&gt;&lt;em&gt;This article applies to:&lt;/em&gt;&lt;/dt&gt;    &lt;dd&gt;&lt;em&gt;SWG 3000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;SWG 5000&lt;/em&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;em&gt;SWG 7000&lt;/em&gt;&lt;/dd&gt;&lt;/dl&gt;&lt;dl style="margin-top: 10px;"&gt;    &lt;dt&gt;&lt;em&gt;&lt;em&gt;This article was previously published as:&lt;/em&gt;    &lt;/em&gt;&lt;/dt&gt;    &lt;dd&gt;&lt;em&gt;&lt;em&gt;Finjan KB 1400&lt;/em&gt;    &lt;/em&gt;&lt;/dd&gt;&lt;/dl&gt;</description><pubDate>Fri, 20 Aug 2010 04:53:44 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>How does the "Add to URL List" feature work?</title><link>https://support.levelblue.com/kb/Goto13653.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;In the Web log viewer, there is an option to add the URL from the Web log entry to a choice of URL Lists. This allows it to be 'blocked' or 'allowed' according to the Security Policy configured by the end-user.&lt;BR&gt;&lt;BR&gt;How does this option work? Not all the customer defined URL lists are displayed in the URL drop-down list, why is this?&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;The "Add to URL list" feature works as follows:&lt;BR&gt;The URL lists displayed in the drop-down menu are the URL lists used by the &lt;U&gt;end user's Security Policy&lt;/U&gt;. &lt;BR&gt;The logic behind this feature is that if the administrator wishes to block or allow a certain URL entry from the Web Logs, it must be done in accordance with the &lt;U&gt;end user's Security Policy&lt;/U&gt; (not according to other URL lists being used by other security policies &lt;STRONG&gt;not &lt;/STRONG&gt;related to this specific end user.)&lt;/P&gt;&lt;P&gt;For example:&lt;BR&gt;The Finjan Medium Security Policy was applied to a specific user and the administrator concludes that this URL should be allowed for this security policy.&lt;BR&gt;In order to do so, the administrator must add the URL entry from the Web log to one of this security policy's URL white lists.&lt;BR&gt;In the Finjan Medium Security Policy there are 7 URL lists in use:&lt;BR&gt;&lt;STRONG&gt;Customer Defined Black List&lt;/STRONG&gt; and &lt;STRONG&gt;URL Black List (Medium):&lt;/STRONG&gt; Used by rule #5, "Block Access to Blacklisted Sites"&lt;BR&gt;&lt;STRONG&gt;Allowed Large Download Sites&lt;/STRONG&gt;, &lt;STRONG&gt;Trusted Sites &lt;/STRONG&gt;and &lt;STRONG&gt;URL Bypass List (Medium):&lt;/STRONG&gt; Used by rule #8, "Allow Trusted Sites"&lt;BR&gt;&lt;STRONG&gt;Customer Defined White List&lt;/STRONG&gt; and &lt;STRONG&gt;URL White List (Medium)&lt;/STRONG&gt;: Used by rule #25, "Allow Access to White Listed Sites"&lt;BR&gt;After clicking on "Add to URL list" these URL lists are indeed listed:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" src="https://support.levelblue.com/kb/attachments/images/1025~Add to URL List.jpg" border=0&gt;&lt;/P&gt;&lt;P&gt;This is the reason that not all URL lists will be displayed in the drop-down menu, but only according to the context of this Web log / URL entry and the security policy of the end user.&lt;BR&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;Versions 9.0 and 9.2&lt;BR&gt;&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1929&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Sun, 02 Aug 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Always click "Commit changes" after editing policy items</title><link>https://support.levelblue.com/kb/Goto13416.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;Why are my latest policy changes not being applied to new transactions?&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;After making any policy-related change (such as editing a rule or a list) in the management console, it is necessary to click the &lt;STRONG&gt;Commit changes&lt;/STRONG&gt; button, as shown below.&lt;BR&gt;&lt;BR&gt;&lt;IMG alt="" src="https://support.levelblue.com/kb/attachments/images/761~CommitChanges.jpg" border=0&gt;&lt;BR&gt;&lt;BR&gt;Clicking on &lt;STRONG&gt;Commit changes&lt;/STRONG&gt; will push the configuration changes to all of the relevant system components, including the Scanning Server.  This is necessary for All in One units as well as distributed environments with a Policy Server and multiple Scanning Servers.&lt;BR&gt;&lt;BR&gt;Almost all changes made in the management console must be committed in order to make them active.  A few changes do not require a commit because only the Policy Server component needs to be aware of them.  Addtionally, changing an IP address in Settings -&amp;gt; Devices will initiate a commit operation automatically, so it is not necessary to click the &lt;STRONG&gt;Commit changes&lt;/STRONG&gt; button.&lt;BR&gt;&lt;BR&gt;When there is any doubt, clicking the &lt;STRONG&gt;Commit changes&lt;/STRONG&gt; button is recommended.  If there are no changes to commit, clicking the button will not cause any harm.  The system will simply warn the administrator that there are no changes to commit, as shown below.  Clicking the &lt;STRONG&gt;Cancel&lt;/STRONG&gt; button will close the window.&lt;BR&gt;&lt;BR&gt;&lt;IMG alt="" src="https://support.levelblue.com/kb/attachments/images/762~CommitNothing.jpg" border=0&gt;&lt;BR&gt;&lt;BR&gt;If the administrator clicks the button and there are pending changes, the system will list the modules that will be affected by the commit operation.  This is depicted in the screenshot that follows.  When the administrator clicks the &lt;STRONG&gt;OK&lt;/STRONG&gt; button, the changes will be committed.  It may take a minute for the commit operation to complete.  It will be finished when all of the IPs in the Network Roles list (Settings -&amp;gt; Devices) have the same configuration revision.&lt;BR&gt;&lt;BR&gt;&lt;IMG alt="" src="https://support.levelblue.com/kb/attachments/images/763~CommitPolicy.jpg" border=0&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.3.X&lt;BR&gt;8.4.X&lt;BR&gt;8.5.0&lt;BR&gt;&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1578&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Sun, 03 May 2009 00:00:00 GMT</pubDate><dc:creator>Eric Hanson</dc:creator></item><item><title>How to block attachments by Gmail and Google Talk</title><link>https://support.levelblue.com/kb/Goto13536.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;How to block attachments from being sent via Gmail and Google Talk services?&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;In order to block attachments from being sent through Gmail and Google Talks, please follow the steps below:&lt;P&gt;1. In the managment console of the Finjan appliance, click on the Lists tab -&amp;gt; URL Lists -&amp;gt; And Create a new URL List called 'Google' as depicted in the screenshot below:&lt;/P&gt;&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/904~URL List.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;2. Click on the new "Google" URL List you've just created, and then click on the Add button in order to insert a value into it. In the URL field insert the word *google* with asterisks before and after the word, click Apply and Commit the changes as depicted below:&lt;/P&gt;&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/905~List.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;3. Click on the Policies tab -&amp;gt; Click on your customized / replicated policy in order to select it and create a new rule, as so:&lt;/P&gt;&lt;P&gt;&lt;div&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/906~New Rule.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;4. In the Rule Editor, give the new rule an appropriate name, such as: 'Block Google Attachments'. Make sure the User Response Action is set to 'Block', and pick a reason page that the end user will see. &lt;/P&gt;&lt;P&gt;Proceed and click on the 'Direction' condition and set it to 'Outgoing'.&lt;/P&gt;&lt;P&gt;Continue and click on the 'URL Lists' condition and make sure you pick the new URL list you just created on steps 1 and 2.&lt;/P&gt;Finally, click on the 'True Content Type' condition and pick all the file types you want to block the user from uploading using Gmail and Google Talk, Click OK and Commit the changes, as depicted in the screenshot below:&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/907~Block.jpg" border=0&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;&lt;P&gt;8.4.3&lt;/P&gt;8.5.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1786&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>Amir Foox</dc:creator></item><item><title>Cannot Export Policy File Using IE Browser</title><link>https://support.levelblue.com/kb/Goto13379.aspx</link><description>&lt;IFRAME src="https://support.levelblue.com/kb/attachments/1529.pdf" width=670 height=800&gt;&lt;/IFRAME&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1529&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Creating a custom message for Coaching in 8.4.3</title><link>https://support.levelblue.com/kb/Goto13335.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;The option to choose a custom defined message for the Coach action in a rule is disabled.&lt;/div&gt;&lt;br&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;In 8.4.3, it is no longer optional to choose a configured message as a reason in a coach action rule.&lt;BR&gt;&lt;BR&gt;(The reason field is grayed out when you choose Coach as a user response action):&lt;BR&gt;&lt;BR&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/647~coach 843.jpg" border=0&gt;&lt;/div&gt;&lt;BR&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;As the Coaching action is only related to the URL policy being violated, it was decided that having more than one type of coaching messages is irrelevant.&lt;/div&gt;&lt;br&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;After defining a custom message for the Coaching action - it will automatically become the default one and will be shown in every Coaching rule.&lt;/div&gt;&lt;br&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.4.3&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1476&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>How to log HTML Repaired transactions?</title><link>https://support.levelblue.com/kb/Goto13516.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;One of the most valuable services provided by Finjan Vital Security for Web appliances is the ability to track the processed information in the logs. &lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, VSOS 8.5.0 and above provides the following logging policies:&lt;/P&gt;&lt;P&gt;   - Log All Protective Actions;&lt;/P&gt;&lt;P&gt;   - Log All Protective Actions and Web Pages;&lt;/P&gt;&lt;P&gt;   - Logging everything except Image files;&lt;/P&gt;&lt;P&gt;The extended logging policy, logging everything except Image files, provides detailed information. However, it has very important constraint causing huge I/O load to the system.&lt;/P&gt;&lt;P&gt;The HTML Repair feature causes malicious scripts on an HTML page to be automatically detected and repaired, and the HTML page is sent on to the end-user in a transparent manner. &lt;BR&gt;Note: The HTML Repair feature is enabled by default.&lt;BR&gt;&lt;BR&gt;Ability to log HTML repaired transcations is one of the reasons users might consider using this logging policy instead of any other alternative.&lt;BR&gt;&lt;BR&gt;This article describes how to create new logging policy that combines the flexibility of the data being logged with the minimal load caused to the system.&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;1. Browse to the Policies section of the management console of Finjan VSOS 8.5.0 and expand the logging policies node. &lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Highlight the default, Log All Protective Actions, logging policy and click Duplicate button on the top as shown below:&lt;/P&gt;&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/868~HTMLrepaired-01.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;3. Set Log Defaults and HTML Repaired Transactions for this new logging policy:&lt;/P&gt;&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/869~new_log_policy.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;4.  Highlight new logging policy and click New Rule button:&lt;/P&gt;&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/870~adding_new_rule.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;5. Rule editor windows pops up. Set this rule conditions as shown below and click OK.&lt;/P&gt;&lt;P&gt;(Set send to archive/log/report/syslog options according to your preferrences)&lt;/P&gt;&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/871~rule_editor.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;5. Decide what should be the place/priority of this rule and move it down with the up/down icons.&lt;/P&gt;&lt;P&gt;Save the policy before you commit these changes.&lt;/P&gt;&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/872~saving.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;6. Commit these changes.&lt;/P&gt;&lt;P&gt;7. Browse to the Users section and set this logging policy for specific user(s) or group(s):&lt;/P&gt;&lt;P&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/873~users_logging.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;8. Apply and commit the changes.&lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.5.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1742&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item></channel></rss>