Quick Start 5: Introducing and configuring Websense Cloud Web Security solution



Similar documents
Quick start 6: Administering the Websense Cloud Web Security solution

Filtering remote users with Websense remote filtering software v7.6

Websense Web Security Gateway: What to do when a Web site does not load as expected

Installing Version 7.6 The Latest Tips

Remote Filtering Software

Migrating your custom settings to version 7.6

Upgrading to Websense Web Security v7.6

Getting Started with TRITON Mobile Security

Controlling Risk, Conserving Bandwidth, and Monitoring Productivity with Websense Web Security and Websense Content Gateway

Quick Start 4: Identifying and Troubleshooting proxy issues for Websense Web Security Gateway

Web-Access Security Solution

WHAT S NEW IN WEBSENSE TRITON RELEASE 7.8

Release Notes for Websense Web Endpoint (32- and 64-bit OS)

Configuration Information

When your users take devices outside the corporate environment, these web security policies and defenses within your network no longer work.

Websense Web Security Gateway: Integrating the Content Gateway component with Third Party Data Loss Prevention Applications

ez Agent Administrator s Guide

Websense Content Gateway HTTPS Configuration

Introduction to Mobile Access Gateway Installation

Centrify Cloud Connector Deployment Guide

Websense Web Security Gateway Anywhere

CounterACT Plugin Configuration Guide for ForeScout Mobile Integration Module MaaS360 Version ForeScout Mobile

WEBSENSE TRITON SOLUTIONS

Installing and Configuring Websense Content Gateway

V Series Rapid Deployment Version 7.5

v7.8.1 Release Notes for Websense Web Security

Websense Content Gateway v7.x: Troubleshooting

Configuration Guide. Websense Web Security Solutions Version 7.8.1

F-SECURE MESSAGING SECURITY GATEWAY

v7.8.2 Release Notes for Websense Content Gateway

Introduction to the Mobile Access Gateway

TRITON - Web Security Help

F-Secure Messaging Security Gateway. Deployment Guide

A Guide to New Features in Propalms OneGate 4.0

Deploying with Websense Content Gateway

Table of Contents. Chapter 1: Installing Endpoint Application Control. Chapter 2: Getting Support. Index

Central Administration User Guide

User Service and Directory Agent: Configuration Best Practices and Troubleshooting

NetSpective Global Proxy Configuration Guide

CIDR Range Subnet Mask /

SSL Decryption: Benefits, Configuration and Best Practices

Configuration Information

Secure Web Appliance. SSL Intercept

WEBSENSE SECURITY SOLUTIONS OVERVIEW


App Orchestration 2.5

Configuring WCCP v2 with Websense Content Gateway the Web proxy for Web Security Gateway

Cyan Networks Secure Web vs. Websense Security Gateway Battle card

Replacing Microsoft Forefront Threat Management Gateway with F5 BIG-IP. Dennis de Leest Sr. Systems Engineer Netherlands

Virtual Web Appliance Setup Guide

Workspot Configuration Guide for the Cisco Adaptive Security Appliance

How To Upgrade A Websense Log Server On A Windows 7.6 On A Powerbook (Windows) On A Thumbdrive Or Ipad (Windows 7.5) On An Ubuntu (Windows 8) Or Windows

Central Administration QuickStart Guide

Web Application Firewall

Setting Up Scan to SMB on TaskALFA series MFP s.

AVG Business Secure Sign On Active Directory Quick Start Guide

Release Notes for Websense Security v7.2

GFI Product Manual. Web security, monitoring and Internet access control. Administrator Guide

What is the Barracuda SSL VPN Server Agent?

vrealize Air Compliance OVA Installation and Deployment Guide

Direct or Transparent Proxy?

Remote Access Clients for Windows

Web Security Gateway Anywhere

Trouble Shooting SiteManager to GateManager access via a corporate Intranet

Endpoint Security VPN for Mac

RemotelyAnywhere Getting Started Guide

Integrated Citrix Servers

REQUIREMENTS AND INSTALLATION OF THE NEFSIS DEDICATED SERVER

TRITON - Web Security Help

Installation Guide Supplement

Filtering and Identifying Web Activity by User Name

A Websense White Paper Implementing Best Practices for Web 2.0 Security with the Websense Web Security Gateway

.trustwave.com Updated October 9, Secure Web Gateway Version 11.0 Hybrid Deployment Guide

IndusGuard Web Application Firewall Test Drive User Registration

Secure Web Service - Hybrid. Policy Server Setup. Release Manual Version 1.01

Trend Micro Worry- Free Business Security st time setup Tips & Tricks

Remote Desktop Gateway. Accessing a Campus Managed Device (Windows Only) from home.

Introduction to the EIS Guide

v7.7.3 Release Notes for Websense Content Gateway

Quickstart guide to Configuring WebTitan

Web Request Routing. Technical Brief. What s the best option for your web security deployment?

Websense Security Transition Guide

Cisco AnyConnect Secure Mobility Solution Guide

The Benefits of SSL Content Inspection ABSTRACT

Endpoint web control overview guide. Sophos Web Appliance Sophos Enterprise Console Sophos Endpoint Security and Control

Installing and Configuring vcenter Support Assistant

Web Security Gateway Solutions

Websense Appliance Manager Help

Remote Filtering Software

F-Secure Internet Gatekeeper Virtual Appliance

Request Manager Installation and Configuration Guide

Lab Testing Detailed Report DR January Competitive Testing of Web Security Devices

Secure Messaging Server Console... 2

Please evaluate this documentation on the following site:

PAC File Best Practices with Web Security Gateway and Web Security Gateway Anywhere

Preparing for GO!Enterprise MDM On-Demand Service

Comprehensive real-time protection against Advanced Threats and data theft

1Y0-250 Implementing Citrix NetScaler 10 for App and Desktop Solutions Practice Exam

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: Security Note

App Orchestration 2.0

Transcription:

Quick Start 5: Introducing and configuring Websense Cloud Web Security solution Websense Support Webinar April 2013 TRITON STOPS MORE THREATS. WE CAN PROVE IT. 2013 Websense, Inc. Page 1

Presenter Greg Didier Title: Support Specialist Accomplishments: 9 years supporting Websense products Qualifications: Technical Support Mentor Product Trainer 2013 Websense, Inc. Page 2

Goals And Objectives Understanding the in-the-cloud concept Software as a Service (SaaS) Web Cloud Security requirements Deployment options Setup and configuration steps I will consider my job successful, if after watching this presentation, you feel confident knowing how to get our Cloud Web service up and running. 2013 Websense, Inc. Page 3

Websense Cloud Platforms Cloud Email Security Email is cleansed before it reaches your network. TRITON Mobile Security Unified security solution for content-aware data, web, malicious app protection, and mobile device management. Cloud Assist (new) Provides on-premises URL analysis and application/protocol detection for Web traffic, along with centralized policy management and reporting capabilities in the cloud. ACE in the Cloud Runs Websense analytics on your incoming Internet traffic. Web Security Gateway Anywhere Combines on-site and in-the-cloud security. Cloud Web Security Gateway Cloud Web Security 2013 Websense, Inc. Page 4

Platform Names Websense Cloud Web Security Gateway Your SSL proxy, analytics, and Cloud security protection Commonly known as Cloud Web Security Gateway Websense TRITON Cloud Web Security Your Cloud security protection Commonly known as Cloud Web Security Formally known as Websense Hosted Web Security Hybrid (in-the-cloud) Combines cloud-based and on-premises filtering» Web Security Gateway Anywhere (V-Series appliance)» Cloud Web Security Gateway Create policies for on-premises and hybrid filtering in a single console TRITON - Web Security 2013 Websense, Inc. Page 5

Software As A Service Worldwide Cloud Security Data Centers Security Filtering Content Analysis Office Home Roaming Traveling Office 2013 Websense, Inc. Page 6

Websense Cloud Web Security Websense Cloud Web Security operates as a proxy service for HTTP, Secure HTTP (HTTPS), and FTP over HTTP. 2013 Websense, Inc. Page 7

Platforms Covered In This Webinar Websense Cloud Web Security 15 worldwide data centers Web Security and Filtering ThreatSeeker Network Office, remote and mobile users Websense Cloud Web Security Gateway 15 worldwide data centers Web Security and Filtering ThreatSeeker Network Office, remote and mobile users Web Proxy + SSL inspection Cloud Endpoint Agent Social Web Controls Executable file analysis Advanced Classification Engine (ACE) Real-Time Content Classification Real-Time Security Classification Antivirus File Analysis Advanced Detection File Analysis Rich Internet Application Analysis 2013 Websense, Inc. Page 8

Getting Started Five steps 1. Request a Cloud Web Security account 2. Select a deployment method 3. Identify your gateway (external IP address) 4. Configuring your Firewall for Cloud Web Security 5. Set up authentication (optional) 2013 Websense, Inc. Page 9

Enabling Cloud Web Security Request an evaluation Visit www.websense.com Select Products > Web Security > Request A Trial Register for Cloud Web Security Gateway Click the registration link in your confirmation email A security check takes 24 business hours Log on to the Cloud Security portal Visit www.mailcontrol.com/login/login_form.mhtml Activate your trail license accept the license agreement 2013 Websense, Inc. Page 10

Enabling Cloud Web Security www.mailcontrol.com/login/login_form.mhtml 2013 Websense, Inc. Page 11

Recap: Enabling Cloud Web Security Request an evaluation Register for Cloud Web Security Gateway Security check Log on to the Cloud Security portal Configure Cloud Web Security via the Web portal Default policy is active Web Security > Policy Management > Policies Demonstration Enable and test Cloud filtering 2013 Websense, Inc. Page 12

Recap: Demonstration Web Content Cloud Security Data Center Known source IP address: 204.15.64.97 Unknown source IP address Off site To determine if a user is roaming, Cloud Web Security uses the source IP address. Corporate Office Corporate Office 2013 Websense, Inc. Page 13

Deployment Decide how you will be sending Web content requests to Websense Cloud Security? Web Content Home Roaming Traveling Office 2013 Websense, Inc. Page 14

Selecting A Deployment Method Websense Cloud Web Security operates as a proxy service Browser Configuration Web Endpoint Proxy Chaining HTTP HTTPS FTP HTTPS traffic tunnels unless decryption is enabled Requires distributing a root certificate to client machines 2013 Websense, Inc. Page 15

Select Deployment Method You must direct Web requests to the Cloud service Proxy chaining If you already have a internal proxy server Direct it to use Cloud Web Security in a chained proxy configuration Configure browsers Proxy automatic configuration (PAC) file Defines an appropriate proxy for fetching a given URL Easily deployed and configurable for entering exclusions Group Policy Object (GPO) Websense Web Endpoint Agent passes authentication information and requests a PAC file to force use of Cloud Web filtering 2013 Websense, Inc. Page 16

Proxy Chaining Configure your existing proxy Forward http, https, and ftp requests Basic chaining NTLM pass-through X-Authenticated-User If your proxy is capable of using a PAC file Use the one provided by Cloud Web Security If your proxy is not capable of using a PAC file Download a copy of the Cloud Web Security PAC file and duplicate its functionality If you make policy changes and are not using the PAC file in your proxy, you must update your proxy configuration to match 2013 Websense, Inc. Page 17

Browser Configuration Via PAC file Browsers must get their PAC file from the Cloud Web Security service Specify either a standard or a policy-specific PAC file Standard PAC file Non-policy specific http://webdefence.global.blackspider.com:8082/proxy.pac Typically used for all users Policy-specific PAC file Specified in the browser Ensure user receives correct PAC file regardless of location Listed in the General screen for each policy, for example: http://webdefence.global.blackspider.com:8082/proxy.pac?p=xxxxx Useful for roaming users 2013 Websense, Inc. Page 18

Recap: Policy-specific Or Standard PAC File Standard Pac file All requests go to the Cloud Service If user cannot log into the Cloud service, he cannot access the Internet Problematic for lost passwords Security Filtering Content Analysis Standard PAC File: No custom URL exceptions Unknown source IP address Roaming user 2013 Websense, Inc. Page 19

Recap: Policy-specific Or Standard PAC File Security Filtering Content Analysis Policy-specific Pac file Allows entering exceptions for direct Web access Allows accessing corporate email to retrieve forgotten passwords Policy- Specific PAC File: Contains your custom URL exceptions Unknown source IP address Roaming user 2013 Websense, Inc. Page 20

Endpoint Client For Hybrid and Cloud Web Security Gateway Not available for Cloud Web Security Ensures users are both authenticated and always filtered by Cloud Web Security Supports 32-bit and 64-bit Mac or Windows operating systems Incorporates protections against tampering Optional auto-update feature 2013 Websense, Inc. Page 21

Endpoint Client Deployment Define an anti-tampering password Download endpoint installer Deploy endpoint client Active Directory group policy object (GPO) msiexec /package "\\path\websense Endpoint.msi" /quiet /norestart WSCONTEXT=xxxx path - is the path to the unzipped installer WSCONTEXT=xxxx from the Endpoint Download screen Associates endpoint clients with your customer account Manually via command line msiexec /package "Websense Endpoint.msi" /norestart WSCONTEXT=xxxx Deploy from cloud or hybrid service Demonstration 2013 Websense, Inc. Page 22

Firewall Ports Minimum open ports 80 Unproxied home page and other direct Cloud support URLs 80 or 8082 Browser or proxy requests for the PAC file 80 or 8081 Provides the Cloud Web Security service 80 and 443 Cloud Security administration Web portal Additional open ports 8088 and 8089 Authentication service and secure form-bases authentication Cloud Cluster IP address Cloud Service cluster IP addresses and port numbers 2013 Websense, Inc. Page 23

Applying Policies Identify the correct policy Checks source IP address Match Proxied Connections setting in a policy Web Endpoint passes authentication details Login with email address Must be unique 2013 Websense, Inc. Page 24

Hybrid Appliance Tips Hybrid Unified on-premises software and off-site hybrid service Appliance sends policies to the hybrid service Cloud Web Security cannot apply polices based on source IP address Hybrid/Cloud can only authenticate synched users 2013 Websense, Inc. Page 25

Additional Tips Stop other applications from bypassing the service Non-Proxied Destinations (exceptions) Can be a domain name, an IP address, or an IP subnet Entries automatically appear in the PAC file Add your corporate Web email address and known good external resource sites Visiting another company Another company's policy may apply. Because you are not a user registered from the source IP address, you can neither log on nor register. Contact the company's Web policy administrator for access. 2013 Websense, Inc. Page 26

Additional Tips Roaming users Set the home page of roaming users to http://home.webdefence.global.blackspider.com This URL is requested over port 80 Cause hotel firewall to respond with the payment page Configure browsers with policy-specific PAC file Your Non-Proxied Destinations are in the PAC file Cloud Web Security works on the basis of source IP 2013 Websense, Inc. Page 27

Cloud Web Security Links Getting Started Guide TRITON Cloud Security Help Websense Cloud Web Security datasheet Websense Cloud Web Security Gateway datasheet Product Comparison Chart Working with Remote Users How do I probe or query the Cloud Web Security service? 2013 Websense, Inc. Page 28

Upcoming Webinar Title: Quick start 6: Administering the Websense Cloud Web Security solution Webinar Update Date: May 22, 2013 Time: 8:30 A.M. PST (GMT -8) How to register: www.websense.com/content/supportwebinars.aspx 2013 Websense, Inc. Page 29

Training Websense Training Partners offer classes online and onsite at your location. For more information, please send email to: readiness@websense.com To find Websense classes offered by Authorized Training Partners in your area, visit: www.websense.com/findaclass 2013 Websense, Inc. Page 30