![Black Box Optinet FE408005AA User Manual Download Page 128](http://html.mh-extra.com/html/black-box/optinet-fe408005aa/optinet-fe408005aa_user-manual_2761491128.webp)
120
match the URL of the web site, some mis-categorization can happen. Finally, if users
attempt to access an HTTPS web site that has been prohibited, they will not receive a
redirection page alerting them that the site has been blocked by Optinet. This is the level of
protection provided by almost all Secure Net Gateway devices that support SSL features.
Enable Denied Access Page for SSL Certificate-Based Content Filtering
This option allows you to filter HTTPS web sites based only on the certificate name present.
In addition to this, this option will only log and filter the first web page accessed for the site.
No other pages on the web site will be scanned. Also, if the certificate name does not
match the URL of the web site, some mis-categorization can happen. However, this option
will present users with a blocked redirection page if the web site has been prohibited and
can be used in conjunction with SSL Certificate-Base Content Filtering.
Enable Full SSL Content Filtering
This option allows you to filter HTTPS web sites based on both the certificate name present,
the name of the web site, and the site’s content. This option is the most robust and
complete of all SSL Filter options as it allows for better categorization of HTTPS web sites,
continued filtering of all pages within the web site, and blocked redirection pages for
prohibited secure sites. Also, this is the only SSL Filter option that offers full scanning of
HTTPS web sites for spyware and virus.
Because of the additional steps required to enable Full SSL Content Filtering, you will not be
able to turn on this option without first contacting a Black Box Network Services Support
Technician. If you are interested in enabling Full SSL Content Filtering, please call Black
Box Network Services Technical Support.
Do not enable Full SSL Content Filtering without deploying The Optinet Digital
Certificate beforehand. Doing so will cause interruption with HTTPS web sites. Please
read the section on Installing The Optinet Certificate before enabling this option.
Only Allow Trusted Certificate Authorities and Non-Expired Certificates
This option will increase security for web traffic as it will not allow users to visit HTTPS sites
that have expired certificates or certificates issued from non-trusted CAs. This option can
be used in conjunction with SSL Certificate-Based Content Filtering and Full SSL Content
Filtering.
HTTPS/SSL Filter Exemption List
This option allows you to enter URLs of secure web sites that will be exempt from SSL
Filtering. For sensitive web sites, such as banking and ecommerce, you may want to enter
the URLs of these sites to avoid content filtering on specific web sites. This option can be
used in conjunction will all SSL filtering options.
Content Filtering Rules
Once you have enabled any of the HTTPS/SSL Filtering options, all your Content Filtering
Rules will now apply to HTTPS web sites. For example, if you have entered myspace in the
Blocked URL list under the Content Filtering tab and enabled HTTPS/SSL Filtering, users will
not be able to access http://www.myspace.com or https://www.myspace.com.