Installing and Configuring Websense Content Gateway



Similar documents
Webinar Information. Title: Websense Remote Filtering Audio information: Dial-in numbers:

Controlling Risk, Conserving Bandwidth, and Monitoring Productivity with Websense Web Security and Websense Content Gateway

Configuring WCCP v2 with Websense Content Gateway the Web proxy for Web Security Gateway

Websense Web Security Gateway: What to do when a Web site does not load as expected

Upgrading to Websense Web Security v7.6

User Service and Directory Agent: Configuration Best Practices and Troubleshooting

v7.8.2 Release Notes for Websense Content Gateway

Websense Content Gateway HTTPS Configuration

SSL Decryption: Benefits, Configuration and Best Practices

Filtering remote users with Websense remote filtering software v7.6

Migrating your custom settings to version 7.6

v7.7.3 Release Notes for Websense Content Gateway

Chapter 6 Configuring the SSL VPN Tunnel Client and Port Forwarding

User and Group-Based Reporting in TRITON - Web Security: Best Practices and Troubleshooting

How To Upgrade A Websense Log Server On A Windows 7.6 On A Powerbook (Windows) On A Thumbdrive Or Ipad (Windows 7.5) On An Ubuntu (Windows 8) Or Windows

HP Vulnerability and Patch Manager 6.0 software Installation and Configuration Guide

LOCKSS on LINUX. CentOS6 Installation Manual 08/22/2013

Virtual Appliance Setup Guide

Configuration Guide. Websense Web Security Solutions Version 7.8.1

Deploying with Websense Content Gateway

Using Integrated Windows Authentication with Websense Content Gateway, v7.6

Getting Started. Websense V10000 Appliance. v1.1

NetSpective Global Proxy Configuration Guide

OnCommand Performance Manager 1.1

Quick Start 5: Introducing and configuring Websense Cloud Web Security solution

Websense Support Webinar: Questions and Answers

Websense Content Gateway v7.x: Troubleshooting

Websense Appliance Manager Help

Virtual Web Appliance Setup Guide

Load Balancing McAfee Web Gateway. Deployment Guide

The SSL device also supports the 64-bit Internet Explorer with new ActiveX loaders for Assessment, Abolishment, and the Access Client.

Websense V-Series Console Help

Syncplicity On-Premise Storage Connector

VMware vcenter Log Insight Getting Started Guide

OS Installation Guide Red Hat Linux 9.0

ZEN LOAD BALANCER EE v3.02 DATASHEET The Load Balancing made easy

ZEN LOAD BALANCER EE v3.04 DATASHEET The Load Balancing made easy

Linux Server Support by Applied Technology Research Center. Proxy Server Configuration

Getting Started. Symantec Client Security. About Symantec Client Security. How to get started

Installation Guide. Websense TRITON Enterprise. v7.8.x

Rally Installation Guide

I N S T A L L A T I O N M A N U A L

Using Red Hat Network Satellite Server to Manage Dell PowerEdge Servers

Virtual Managment Appliance Setup Guide

Load Balancing Trend Micro InterScan Web Gateway

Proof of Concept Guide

NEFSIS DEDICATED SERVER

SuperLumin Nemesis. Administration Guide. February 2011

F-Secure Internet Gatekeeper Virtual Appliance

Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice.

Websense Appliance Manager Help

emerge 50P emerge 5000P

AT&T CLOUD SERVICES. AT&T Synaptic Compute as a Service SM : How to Get Started. Version 2.0 January 2012

GlobalSCAPE DMZ Gateway, v1. User Guide

Secure Web Appliance. SSL Intercept

REQUIREMENTS AND INSTALLATION OF THE NEFSIS DEDICATED SERVER

F-Secure Messaging Security Gateway. Deployment Guide

TRITON - Web Security Help

User Guide. Cloud Gateway Software Device

Network Security Platform 7.5

Integrated SSL Scanning

Deploying Windows Streaming Media Servers NLB Cluster and metasan

Cisco Application Networking Manager Version 2.0

Hardware and Software Requirements for Server Applications

TimeIPS Server. IPS256T Virtual Machine. Installation Guide

Cloud.com CloudStack Community Edition 2.1 Beta Installation Guide

Quick Install Guide. Lumension Endpoint Management and Security Suite 7.1

DameWare Server. Administrator Guide

Deployment Guide Microsoft IIS 7.0

Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0

Web Application Firewall

HOMEROOM SERVER INSTALLATION & NETWORK CONFIGURATION GUIDE

Kaspersky Endpoint Security 8 for Linux INSTALLATION GUIDE

Preinstallation Requirements Guide

Very Large Enterprise Network Deployment, 25,000+ Users

Release Notes for Version

Uptime Infrastructure Monitor. Installation Guide

Installing and Configuring vcenter Support Assistant

GFI Product Manual. Web security, monitoring and Internet access control. Administrator Guide

F-SECURE MESSAGING SECURITY GATEWAY

Sophos UTM Software Appliance

SSL VPN Server Guide Access Manager 3.1 SP5 January 2013

Cisco IP Communicator (Softphone) Compatibility

Getting Started. Websense V-Series Appliance V10000, V10000 G2, V10000 G3, and V5000 G2. v7.7.x

V Series Rapid Deployment Version 7.5

Customer Site Requirements for incontact Workforce Optimization

Ekran System Help File

A Guide to New Features in Propalms OneGate 4.0

Semantic based Web Application Firewall (SWAF - V 1.6)

QUICK START GUIDE. Cisco S170 Web Security Appliance. Web Security Appliance

Deployment Guide. Websense Web Security Websense Web Filter. v7.1

Remote Filtering. Websense Web Security Websense Web Filter. v7.1

Common Services Platform Collector 2.5 Quick Start Guide

OnCommand Performance Manager 2.0

Transcription:

Installing and Configuring Websense Content Gateway Websense Support Webinar - September 2009 web security data security email security Support Webinars 2009 Websense, Inc. All rights reserved.

Webinar Information Title: Installing and Configuring Websense Content Gateway Audio information: This presentation incorporates STREAMING AUDIO. Use of speakers or headsets is required. If unable to hear streaming audio or it is choppy, a limited number of dial-in numbers are available. Dial-in numbers: U.S. dial-in numbers: Toll free: 1-888-373-5705, pass-code: 977210 Toll: 1-719-457-3840, pass-code: 977210 Find international dial-in numbers at: http://www.websense.com/septemberintlnumbers Pass-code: 977210 2

Webinar Presenter Greg Didier Title: Tech Support Specialist Accomplishments: Over 5 years supporting Websense products Certifications: Security & Network design MCP WCWSA Websense Certified Web Security Associate Qualifications: Trainer For additional information: www.websense.com/support/ 3

Goals and Objectives Preinstall considerations Check Linux server Install Websense Content Gateway (WCG) Enable HTTPS Create and deploy certificates Test filtering 4

Pre-install Requirement Websense Web Security Gateway must be installed before you install Websense Content Gateway. The integration mode must be Websense Content Gateway. 5

Hardware Requirements CPU quad-core, 2.8 GHz or faster Memory 4 GB RAM Disk Space two disks 100 GB disk for Red Hat Linux, Websense Content Gateway, temporary data 147 GB disk (max size) for caching Must be a raw disk Must be dedicated Must not be part of a RAID Network Interfaces One NIC for non-clustered setup Two NICs for a clustered configuration 6

Software Requirements Linux only Red Hat Enterprise, Advanced Server, release 4, update 5, kernel 2.6.9-55 May use the Minimal Linux install option RPM compat-libstdc++-33-3.2.3-47.3.i386.rpm is required 32-bit Websense Filtering integration Websense Web Security Gateway v7.1 Websense Web Security v7.1 Websense Web Filter v7.1 Supported browsers Internet Explorer 7 or 8 Mozilla Firefox 2 or 3 7

Websense Content Gateway In Your Network Internet Websense Web Security Gateway Explicit Request Websense Content Gateway Gateway Workstation Router Firewall 8

Ports Ports used for Websense Content Gateway 21 TCP (Transparent FTP proxy) 22 TCP (SSH) 53 and 5353 UDP (DNS requests) 80 TCP (Transparent HTTP proxy) 443 TCP (Transparent HTTPS proxy) 2048 UDP (WCCP) 2121 TCP (Explicit FTP proxy) 8070 TCP (Explicit HTTPS proxy) 8071 and 8081 TCP (Proxy management interface) 8080 TCP (Explicit HTTP proxy) 8082 8090, 3031 TCP (Required only if clustering proxies) 40000, 55806, 55880, 55905 TCP (Local Websense Policy Server) 55807, 15868 TCP (Local Websense Filtering Service) 65535 TCP (Remote Websense Policy Server or Filtering Service) 9

Review Linux Configuration Pre-install check list for Websense Content Gateway Linux version IP configuration Hostname IP / hostname resolution Routing table DNS IPv6 is disabled Date and time SELinux is disabled Iptables Demonstration 10

Installing Websense Content Gateway Linux IPTables (the firewall) See KB 4106: Configuring IPTables for Websense Content Gateway Install files www.mywebsense.com Knowledge Base article # 4191 Title: v7: Accessing Websense Content Gateway downloads Move files to Linux server WinSCP secure file transfer utility Install Websense Content Gateway Using putty Demonstration 11

Review Linux Configuration 12

IP Configuration 13

IP Configuration 14

IP Configuration 15

Hostname 16

IP / Hostname Mapping 17

Routing 18

Checking DNS 19

Checking DNS 20

Activating Websense Content Gateway Install Manager certificate Enter subscription key Websense Content Gateway and Websense Web Security Gateway use the same key Websense Content Gateway services Status check Verify Websense Web Security Gateway is integrated with Websense Content Gateway Filtering service install type Demonstration 21

Troubleshooting Failed install, review: OS and kernel version Proper libraries (RPMs) installed Hostname and host file Ethernet settings DNS configuration IPv6 disabled Iptables correctly configured SELinux disabled Date and time match on Websense Content Gateway and Websense Web Security Gateway Internet connectivity Once the problem is identified and corrected Reinstall Websense Content Gateway 22

Initial Configuration of Websense Web Security Gateway Downloading the Master Database via the proxy Scanning options Identify the Log Server location Configure Network Agent Demonstration 23

SSL Content Inspection Enable HTTPS Create a self-signed certificate Backup the self-signed certificate Restart Websense Content Gateway Test SSL Import the certificate into the Trusted Root CA Store Demonstration 24

Allowing HTTPS Web sites Certificate validation Working with incidents Tunneling a Web site Demonstration 25

Disabling IPv6 Disabling IPv6 /etc/modprobe.conf Remove one entry net-pf-10 ipv6 Add two entries alias net-pf-10 off alias ipv6 off Disabling IPv6 26

Disabling IPv6 27

Date 28

Disabling SELinux 29

Disabling SELinux 30

Disabling SELinux 31

Disabling SELinux 32

IPTables The Linux Firewall 33

IPTables The Linux Firewall 34

IPTables The Linux Firewall 35

IPTables The Linux Firewall 36

IPTables The Linux Firewall IPTables Knowledge Base article 4106 Title: Configuring IPTables for Websense Content Gateway Batch script attached to KB article Logon into www.mywebsense.com/support Choose the Websense Security Gateway knowledge base 37

Reboot 38

Installing Websense Content Gateway Install file www.mywebsense.com Knowledge Base article # 4191 Title: v7: Accessing Websense Content Gateway downloads Install Websense Content Gateway Using putty Demonstration 39

Installing Websense Content Gateway 40

Installing Websense Content Gateway 41

Installing Websense Content Gateway 42

Installing Websense Content Gateway 43

Installing Websense Content Gateway 44

Installing Websense Content Gateway 45

Installing Websense Content Gateway 46

Installing Websense Content Gateway 47

Installing Websense Content Gateway 48

Installing Websense Content Gateway 49

Installing Websense Content Gateway 50

Installing Websense Content Gateway 51

Installing Websense Content Gateway 52

Troubleshooting Failed install, review: OS and kernel version Proper libraries (RPMs) installed Hostname and host file Ethernet settings DNS configuration IPv6 disabled Iptables correctly configured SELinux disabled Date and time match on Websense Content Gateway and Websense Web Security Gateway Internet connectivity Once the problem is identified and corrected Reinstall Websense Content Gateway 53

Troubleshooting 54

Activating Websense Content Gateway Enter subscription key Websense Content Gateway and Websense Web Security Gateway use the same key Websense Content Gateway services Status check Verify Websense Web Security Gateway is integrated with Websense Content Gateway Filtering Service install type Demonstration 55

Activating Websense Content Gateway Logging into the Websense Content Gateway https://<ip address>:8081 56

Activating Websense Content Gateway 57

Activating Websense Content Gateway 58

Activating Websense Content Gateway 59

Activating Websense Content Gateway 60

Activating Websense Content Gateway 61

Activating Websense Content Gateway 62

Activating Websense Content Gateway 63

Activating Websense Content Gateway 64

Activating Websense Content Gateway 65

Initial Configuration of Websense Web Security Gateway Downloading the Master Database via the proxy Scanning options Identify the Log Server location Configure Network Agent Demonstration 66

Initial Configuration of Websense Web Security Gateway Logging into the Manger https://<ip address>:9443 67

Initial Configuration of Websense Web Security Gateway 68

Initial Configuration of Websense Web Security Gateway 69

Initial Configuration of Websense Web Security Gateway 70

Initial Configuration of Websense Web Security Gateway 71

Initial Configuration of Websense Web Security Gateway 72

Initial Configuration of Websense Web Security Gateway 73

Initial Configuration of Websense Web Security Gateway 74

SSL Content Inspection Enable HTTPS Create a self-signed certificate Backup the self-signed certificate Restart Websense Content Gateway Import the certificate into the Trusted Root CA Store Test SSL Demonstration 75

Allowing HTTPS Web sites Certificate validation Working with incidents Tunneling a Web site Demonstration 76

Support Online Resources Tech Alerts Subscribe to receive product specific alerts that automatically notify you anytime Websense issues new releases, critical hotfixes, or other technical information. Knowledge Base Search or browse the knowledge base for documentation, downloads, top knowledge base articles, and solutions specific to your product. Support Forums Share questions, offer solutions and suggestions with experienced Websense Customers regarding product Best Practices, Deployment, Installation, Configuration, and other product topics. ask.websense.com Create and manage support service requests using our online portal.

Webinar Announcement Title: Common Configuration Methodologies for Websense Content Gateway Webinar Update Date: October 28, 2009 Time: 8:30 AM Pacific Time How to register: http://www.websense.com/content/supportwebin ars.aspx

Customer Training Options To find Websense classes offered by Authorized Training Partners in your area, visit: http://www.websense.com/findaclass Websense Training Partners also offer classes online and onsite at your location For more information, please send email to: readiness@websense.com

Questions? 80