119
SSL CGI Proxy
This type of proxy has users enter the Universal Resource Locator (URL) of the web site
they want to browse to into a web form. The web site then processes the request and
retrieves the page on behalf of the user. The web sites changes the links and images within
the page so that the requests are actually hosted by the proxy web site and not the original
web site.
SSL Full Proxy
This type of proxy requires users to modify their web browser settings to use a proxy
server. Some of these sites will also use non-standard ports to conceal web traffic.
SOCKS4/5 Proxy
This type of proxy also has users modify web browser settings to use a proxy server.
TorPark Network
This type of proxy is a SSL based network that allows users to hide web browsing. TorPark
normally uses non standard port numbers to avoid detection and uses SSL to conceal the
content of web sites.
Optinet has several options that allow you to block Anonymous SSL web surfing and users
from concealing their traffic. These options are discussed in the next section.
HTTPS/SSL Filtering
Optinet offers you several tools to filter HTTPS/SSL traffic, and to block proxy web sites that
allow users to cover their web traffic. Depending upon the type of control you want over
SSL traffic, you will need to configure HTTPS/SSL Filtering accordingly. All HTTPS/SSL
filtering options are handled by Traffic Flow Rule Sets (TFRS).
TFRS are the basic traffic identification and control engine within Optinet. TFRS allow you to
dictate how traffic will be identified, controlled, reported, filtered and shaped. In the case of
HTTPS/SSL traffic, Optinet has several TFRS that will handle HTTPS/SSL traffic according to
the settings listed below.
The component of TFRS that handle HTTPS/SSL Filtering is called SSL Filter. SSL Filter can
perform content filtering, web logging, spyware scanning, and virus scanning on all HTTPS
web sites. However, there are several options with SSL Filtering. Below are all available
options.
Disable SSL Inspection and Filtering
This option will not perform any HTTPS/SSL Filtering or Inspection. This is the default
option and will not filter, report, or inspect any HTTPS/SSL traffic.
Enable SSL Certificate-Based Content Filtering
This option allows you to filter HTTPS web sites based only on the certificate name present.
In addition to this, this option will only log and filter the first web page accessed for the site.
No other pages on the web site will be scanned. Also, if the certificate name does not