background image

B

EST

 F

ILTERING

 

AND

 R

EPORTING

 P

RACTICES

    

W

EB

 F

ILTER

 U

SAGE

 S

CENARIOS

72

M86 S

ECURITY

 I

NSTALLATION

 G

UIDE

10. Remote Access patterns

Block remote access patterns

. Enable Pattern Blocking for all users. In the 

profile, block Internet Productivity > Remote Access category.

To block remote access patterns, go to:
• SYSTEM: System > Control > Filter window
• POLICY: Policy > IP > member > member profile > Category tab

or POLICY: Policy > Global Group > Global Group Profile > Category tab

In the WFR User Guide index, see:
• How to: configure filtering
• How to: use library categories in a profile

11. HTTPS settings

Establish the security level for HTTPS site access

. Configure HTTPS filter 

settings in the Filter window. Choose “None” if you do not want the Web Filter to 
filter HTTPS sites, “Low” if you want the Web Filter to filter HTTPS sites without 
having the Web Filter communicate with IP addresses or hostnames of HTTPS 
servers, “Medium” if you want the Web Filter to communicate with HTTPS servers 
in order to get the URL from the certificate for URL validation only (this is the 
default setting), or “High” if you want the Web Filter to communicate with HTTPS 
servers to obtain the certificate with a very strict validation of the return URL.

To configure HTTPS settings, go to:
• SYSTEM: System > Control > Filter window

In the WFR User Guide index, see:
• How to: configure filtering

12. Category block

Block the Bandwidth category

. Set the Bandwidth category to be blocked in 

pertinent profiles.

To block the Bandwidth category, go to:
• POLICY: Policy > IP > member > member profile > Category tab

or POLICY: Policy > Global Group > Global Group Profile > Category tab

In the WFR User Guide index, see:
• How to: use library categories in a profile

Summary of Contents for 350

Page 1: ...M86 Web Filter and Reporter INSTALLATION GUIDE Models 350 550 Software Version 2 0 10 Document Version 06 22 10...

Page 2: ...cument However M86 Security makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose M86 Security shall not b...

Page 3: ...s Servers 7 Rack Setup Suggestions 7 Install the Inner Slides 7 Install the Outer Slides 7 Install the Slide Assemblies to the Rack 8 Install the Chassis into the Rack 9 Install the Bezel on the 500 S...

Page 4: ...D Menu 27 M86 menu 28 WF Filter Mode 29 IP LAN1 and 2 29 Gateway 29 DNS 1 and 2 30 Host Name 30 Regional Setting Time Zone date time 30 TAR GUI Wizard User 31 Non Quick Start procedures or settings 31...

Page 5: ...itoring 58 Step 8 Verify Web Filter Log Transfer 60 Single Sign On Access Default Username Password 61 Access WFR Applications from the TAR User Interface 61 Default Usernames and Passwords for WFR Ap...

Page 6: ...ith the highest score 82 Step B Investigate a user s activity in a specified gauge 84 Step C Investigate the user s Internet activity in other gauges 85 III Create a gauge exercise 86 Step A Access th...

Page 7: ...on Screen 107 ER Web Client ER Server Information Window 108 LED INDICATORS AND BUTTONS 109 Front Control Panel on 500 Series Unit 109 Front Control Panel on a 300 Series Unit 110 REGULATORY SPECIFICA...

Page 8: ...CONTENTS viii M86 SECURITY INSTALLATION GUIDE...

Page 9: ...ic supported by remediation tools to manage and control user generated Web threats Working in conjunction with the Web Filter TAR interprets end user Internet activity from the Web Filter s logs and s...

Page 10: ...explains how to read LED indica tors and use LED buttons for troubleshooting the unit Regulatory Specifications and Disclaimers This section cites safety and emissions compliance information for the W...

Page 11: ...rters USA Local 714 282 6111 Domestic US 1 888 786 7999 International 1 714 282 6111 M86 Security Taiwan Taipei Local 2397 0300 Domestic Taiwan 02 2397 0300 International 886 2 2397 0300 Procedures Wh...

Page 12: ...el to be installed on the front of the chassis 1 set of rack mounting rails For 300 series models the following items are also included in the carton 1 power adapter with power cord 1 set of 4 pressur...

Page 13: ...ll outlet this is the only way to remove the AC power cord from the server Clearance provided for cooling and airflow Approximately 30 inches 76 2 cm in the back and 25 inches 63 5 cm in the front Loc...

Page 14: ...nection of the server to the power supply will not overload any circuits Consideration should be given to the connection of the equipment to the supply circuit and the effect that overloading of the c...

Page 15: ...right inner slide against the hooks on the right side of the chassis as show below on the left 3 Securely attach the slide to the chassis with two M4 flat head screws and repeat the steps 1 3 to insta...

Page 16: ...to the Rack 1 After you have installed the short and long brackets to the outer slides you are ready to install the whole slide assemblies outer slides with short and long brackets attached to the ra...

Page 17: ...IDE 9 Install the Chassis into the Rack 1 Push the inner slides which are attached to the chassis into the grooves of the outer slide assemblies that are installed in the rack as shown below 2 Push th...

Page 18: ...5 on the inside of the U shaped aluminum rail handles on both ends of the chassis rails Fig 4 U shaped handles Note also that the holes for the longer pair of pins are located on the front of the chas...

Page 19: ...rican and Pacific Rim countries Power Supply Precautions WARNING Use a regulating uninterruptible power supply UPS to protect the server from power surges voltage spikes and to keep the server operati...

Page 20: ...e result could be dangerous heat and even fire CAUTION There are no user serviceable components inside the chassis The chassis should only be opened by qualified service personnel Never disassemble ta...

Page 21: ...Electrical Safety Precautions WARNING Heed the following safety precautions to protect yourself from harm and the server from damage CAUTION Dangerous voltages associated with the 100 240 V AC power...

Page 22: ...There is a danger of explosion if the battery on the motherboard is installed upside down which will reverse its polarities CAUTION DANGER OF EXPLOSION IF BATTERY IS INCORRECTLY REPLACED REPLACE ONLY...

Page 23: ...ptop computer with HyperTerminal and serial port cable and USB DB9 serial adapter if there is no serial port on your laptop B Go to Step 1A to execute Quick Start Setup Procedures NOTE For 300 series...

Page 24: ...r C Proceed to the next set of instructions Power on the WFR Serial Console Setup A Using the serial port cable and USB DB9 serial adapter if necessary connect the laptop to the rear of the chassis se...

Page 25: ...nning proceed to the following set of instructions For Monitor and Keyboard Setup go to Login screen For Serial Console Setup go to HyperTerminal Setup Procedures Power up a 500 Series Model A Make su...

Page 26: ...ram installed on your workstation Hilgraeve Inc the maker of HyperTerminal offers HyperTerminal Private Edition for Windows Vista and Windows 7 The following information is included on Hilgraeve s Web...

Page 27: ...t assigned to the serial port on the laptop probably COM1 and then click OK to open the Properties dialog box displaying the Port Settings tab D Specify the following session settings Bits per second...

Page 28: ...ATION GUIDE F In the HyperTerminal session window go to File Properties to open the Prop erties dialog box displaying the Connect To and Settings tabs G Click the Settings tab and at the Emulation men...

Page 29: ...tly displays on your screen press the Enter key to display the login screen A At the login prompt type in menu B Press the Enter key to display the Password prompt C At the Password prompt type in the...

Page 30: ...er NOTE Please make a note of the LAN 1 and LAN 2 IP address and host name you assign to the WFR server as well as the username and password you create for logging into the setup wizard as you will ne...

Page 31: ...tart menu press 5 to go to the Configure Network Interface screen for LAN2 B At the Enter interface LAN2 IP address prompt type in the LAN2 IP address and press Enter C At the Enter interface LAN2 net...

Page 32: ...TE If this server is located in the USA please select US and not America C After you select the region you may be prompted to select the locality within the selected region Select the locality and pre...

Page 33: ...etting the Web Filter Administrator console username and password to the factory default admin user3 and for unlocking all IP addresses currently locked B At the Enter the new administrator password p...

Page 34: ...teway IP address specified in screen 6 Configure default gateway host name for the Web Filter specified in screen 8 Configure host name DNS server IP address es specified in screen 7 Configure DNS ser...

Page 35: ...NTER keys 300 series keypad at left 500 series keypad at right To display software status information about the WFR press the right arrow key To go to the LCD Menu press X CANCEL Pressing X CANCEL aga...

Page 36: ...ng the M86 menu to execute quick start setup procedures be sure to configure all menu items marked in the list above with an asterisk Please make a note of the LAN 1 and LAN 2 IP address and host name...

Page 37: ...e current value and the left right arrow keys to navigate across the line C Press the checkmark ENTER key to accept your entry and to return to the previous screen D Choose Change LAN1 2 Netmask and p...

Page 38: ...n first uppercase and then lowercase numbers from 0 9 and lastly the symbol characters NOTE Navigation tips If the down arrow key is pressed first instead of the right arrow key the symbol characters...

Page 39: ...lays Reset WF Admin Console Password When the Reset Admin Console Password option is selected the Reset Admin Console screen displays with a WARNING menu item A Choose WARNING to display the message s...

Page 40: ...ion reboots the WFR No cancel reboot This selection returns you to the previous screen B Press the X CANCEL key to return to the M86 menu Shutdown When the Shutdown option is selected the Shutdown scr...

Page 41: ...iew each of the three available options backlight feature enabled populated field backlight turns on backlight feature disabled empty field backlight turns off display the backlight now populated fiel...

Page 42: ...he WFR s LAN 1 port the port on the left Rear of 300 series chassis with LAN ports identified Portion of 500 series chassis rear with LAN ports identified B Plug the other end of the CAT 5E cable into...

Page 43: ...issue page If using Firefox proceed to Accept the Security Certificate in Firefox If using IE proceed to Temporarily Accept the Security Certificate in IE If using Safari proceed to Accept the Securit...

Page 44: ...N GUIDE Accept the Security Certificate in Firefox A If using a Firefox browser in the page This Connection is Untrusted click the option I Understand the Risks B In the next set of instructions that...

Page 45: ...Web Client Enterprise Reporter Administration Module and Threat Analysis Reporter when you attempt to access each of these applications for the first time On a newly installed unit the ER Web Client w...

Page 46: ...If using an IE browser in the page There is a problem with this website s security certificate click Continue to this website not recommended Selecting this option displays the WFR Welcome window with...

Page 47: ...verify the identity of the website opens Click Show Certificate to open the certificate information box at the bottom of this window B Click the Always trust checkbox and then click Continue C You wi...

Page 48: ...e TAR icon After clicking the TAR icon and accepting a security exception for the TAR application if necessary the EULA Agreement dialog box opens B After reading the End User License Agreement click...

Page 49: ...etup wizard user screen of the Quick Start Setup Procedures Step 1A or the TAR GUI Wizard screen in LCD Panel Setup Procedures Step 1B B In the Password field type in the password specified in the Con...

Page 50: ...obal administrator who will be notified via email regarding system alerts C Enter the Password to be used with that username and enter the same pass word again in the Confirm Password field Enter Band...

Page 51: ...Reporter Other wise leave the checkbox blank D Click Add to include your entries in the list box below NOTES Additional Web Filters can be included by following steps A through D again The Source Web...

Page 52: ...elf signed certificate so your browser will recognize the WFR as an accepted device A In the Threat Analysis Reporter login window type in the Username and Pass word registered for the TAR Wizard B Cl...

Page 53: ...application server would restart Would you like to continue E Click Yes to begin the process Once the self signed certificate has been gener ated you will be logged out of TAR and the WFR server will...

Page 54: ...wser Windows XP or Vista with IE 7 or 8 Windows 7 with IE 8 Windows XP or Vista with IE 7 or 8 A If using an IE 7 or 8 browser on a Windows XP or Vista machine in the page There is a problem with this...

Page 55: ...CURITY INSTALLATION GUIDE 47 Figure A2 Windows XP IE 7 B Click Certificate Error to open the Certificate Invalid pop up box Figure B Windows XP IE 7 C Click View certificates to open the Certificate w...

Page 56: ...ERTIFICATE 48 M86 SECURITY INSTALLATION GUIDE Figure C Windows XP IE 7 D Click Install Certificate to launch the Certificate Import Wizard Figure D Windows XP IE 7 E Click Next to display the Certific...

Page 57: ...close the pop up box H Click Next to display the last page of the wizard Figure H Windows XP IE 7 I Click Finish to close the wizard and to open the Security Warning dialog box asking if you wish to...

Page 58: ...nd the Certificate Error button to the right of the field shaded a reddish color see Figure A2 Click Certificate Error to open the Certificate Invalid pop up box see Figure B Click View certificates t...

Page 59: ...ddress to the Server s Host Name Map the WFR s IP Address to the Server s Host Name A From your workstation launch Windows Explorer and enter C WINDOWS system32 drivers etc in the Address field to ope...

Page 60: ...rt Setup Procedures Step 1A or the Host Name screen in LCD Panel Setup Proce dures Step 1B and then save and close the file D In the address field of your newly opened IE browser from now on you will...

Page 61: ...tested If you do not contact an M86 Security solutions engineer or technical support representative Test the Mobile Client Connection If the Web Filter has been set up to use the Mobile mode you shou...

Page 62: ...your account A Open an Internet browser window and go to http www m86security com support activate appliance asp B After reading through the online End User License Agreement click Accept to go to Ste...

Page 63: ...lick the icon corresponding to Web Filter After clicking the Web Filter icon and accepting a security exception for the Web Filter application if necessary the Web Filter Administrator console login w...

Page 64: ...you begin using the Web Filter you must perform a complete library update to ensure you have the latest library updates To download the latest library updates A Click the Library button at the top of...

Page 65: ...og to display the update activity NOTE You will be notified in the log when the library has been completely updated by the message Full URL Library Update has completed If this message does not yet di...

Page 66: ...rresponding to Enterprise Reporter Administration Module After clicking the ER Admin Module icon and accepting a security exception for the ER Admin Module application if necessary the ER Administrato...

Page 67: ...bout using the ER in the Evaluation Mode for more details about the evalua tion mode C From the Server pull down menu choose Self Monitoring to display the Self Monitoring screen D Choose YES to activ...

Page 68: ...e ER Administrator console B Go to the Database pull down menu and choose Tools to display the Tools screen C From the Database Status menu select File Watch Log The transfer is working if you see an...

Page 69: ...ord 2 Go to the navigation links at the top of the screen and select Report Analysis Web Filter IP address to access the Web Filter user interface Report Analysis Enterprise Reporter Web Client to acc...

Page 70: ...ted this generally takes a full day the ER Web Client can be used for generating reports Initially you will only be able to report on IP addresses To implement user names in ER reporting please consul...

Page 71: ...get sources of unusually high Internet activity create a gauge that will monitor a user group s Internet activity set up an email alert for notification of potential Internet usage threats on the netw...

Page 72: ...rio M86 Security s filtering library currently consists of 104 library filtering categories each placed in one of the 20 filtering category groups defined in the interface Adult Content Bandwidth Busi...

Page 73: ...categories in a profile go to POLICY Policy Global Group Rules Policy IP member member profile Category tab or Policy Global Group Global Group Profile Category tab In the WFR User Guide index see Ho...

Page 74: ...L keywords to be blocked go to LIBRARY Library Category Groups category URL Keywords POLICY Policy IP member member Profile Filter Options tab URL Keyword Filter Control enabled or POLICY Policy Globa...

Page 75: ...to POLICY Policy Global Group Minimum Filtering Level Policy Global Group Global Group Profile Category tab In the WFR User Guide index see How to configure the Minimum Filtering Level How to use lib...

Page 76: ...rofile Category tab In the WFR User Guide index see How to configure filtering How to use library categories in a profile 12 File type blocking Prevent users from downloading and using executable file...

Page 77: ...ategories in a profile 2 Overall Quota Restrict all quota time in a profile to improve bandwidth usage and produc tivity Cap the amount of time a user spends in all quota marked categories by enabling...

Page 78: ...e Warn feature along with X Strikes Blocking After the end user is warned for the designated number of times defined in X Strikes Blocking that user is locked out of all Internet intranet access To se...

Page 79: ...g for all users In the profile block Entertainment Games category To block game patterns go to SYSTEM System Control Filter window POLICY Policy IP member member profile Category tab or POLICY Policy...

Page 80: ...HTTPS sites Low if you want the Web Filter to filter HTTPS sites without having the Web Filter communicate with IP addresses or hostnames of HTTPS servers Medium if you want the Web Filter to communic...

Page 81: ...o to LIBRARY Library Category Groups category group category Search Engine Keywords POLICY Policy IP member member Profile Filter Options tab Search Engine Keyword Filter Control enabled or POLICY Pol...

Page 82: ...em Customization Common Customization window and other applicable customization windows In the WFR User Guide index see How to customize pages 17 Real Time Probe information Monitor Internet usage act...

Page 83: ...rike with higher thresholds Warn users before they access unacceptable content and may be locked out of the Internet Set HTTPS filtering at the high level configure Warning settings and enable X Strik...

Page 84: ...Based Profiles Schedule a profile to be used at a specific time Set up one or more profiles for each user or group to be active at a scheduled time To set up and use time profiles go to POLICY Policy...

Page 85: ...nt in a Custom category Set up a custom cate gory that only includes content pertinent to your organization or region that should be blocked Apply this category to a profile To create a Custom Categor...

Page 86: ...ofile 2 URL exceptions Use Exception URLs to let specified individuals bypass the Minimum Filtering Level Enable the option to bypass the Minimum Filtering Level using exception URLs Enter the excepti...

Page 87: ...lobal Group level go to POLICY Policy Global Group Override Account window To configure the bypass feature and set up a group level override account go to POLICY Policy Global Group Minimum Filtering...

Page 88: ...e Gauges section The URL dashboard displays by default after you log into the console This main screen is comprised of a banner and dashboard below The navigation portion of the banner includes six li...

Page 89: ...cessing appliances connected to the WFR to perform a search on user URL bandwidth activity or to generate a report showing activity in all URL or bandwidth gauges Web Filter access the Web Filter to c...

Page 90: ...In the WFR User Guide index see How to navigate the TAR user interface II Drill down into a gauge exercise This exercise will teach you how to drill down into a URL gauge to conduct an investigation o...

Page 91: ...core to open the Threat View User panel Note the left side of this panel is populated with rows of records for Threats affected by the selected end user Now that you ve identified the user affecting t...

Page 92: ...the high scoring threat select the Threat with the highest score and then click it to display a list of URLs the user visited in the right side of this panel 2 Choose a URL you wish to view and then...

Page 93: ...o the Gauge Ranking table by going to the lower left corner of the Threat View User panel and clicking the Back button In the User Name column click that user s link to display the User Summary panel...

Page 94: ...d users are driving the score in one or more gauges and how to view URLs visited by the user When you become accustomed to using the Threat Analysis Reporter on a regular basis to conduct these types...

Page 95: ...racking gauge activity 1 60 minutes For this exercise we will use the default and recommended value which is 15 minutes d Gauge Method to be used for tracking gauge activity For this exercise we will...

Page 96: ...er Groups list select the user group to highlight it 6 Click add to move the user group to the Assigned User Groups list box 7 After adding users click Save at the bottom right of the panel to return...

Page 97: ...deal in real time with Internet usage issues that endanger your network and or consume an excessive amount of bandwidth resources IV Create an email alert exercise This exercise will teach you how to...

Page 98: ...yed out target panel to the right containing the Email Addresses and Low Lockout Components accordions 4 Type in the Alert Name to be used for the alert that will be delivered to the group administrat...

Page 99: ...ld limit set up in a gauge alert For this exercise however you will only want to select Email as described in the next step In the WFR User Guide index see How to add a new alert Step C Select Email A...

Page 100: ...mail address that was specified The email alert identifies the end user who triggered the alert and includes a list of URLs the user visited along with the date and time each URL was accessed Clicking...

Page 101: ...that there are two basic types of Drill Down Reports summary and detail reports and various types of reports you can generate for each of these two basic drill down report types Step A Start with the...

Page 102: ...vestigation From the top panel go to Drill Down Reports Categories to display the gener ated Summary Drill Down Report view ranking categories in order by the most visited Note that this drill down re...

Page 103: ...o create a New Report from the current report view Step D Create a double break report with two sets of criteria 1 To continue this exercise select the record for the category you wish to further inve...

Page 104: ...this exercise you will select a user from the current Summary Drill Down Report view and then drill down further to see which URLs that user visited thereby creating a Detail Drill Down Report view St...

Page 105: ...have also learned how to change the date scope of a Drill Down Report to create a new report generate a double break report view to include two sets of criteria and drill down into the current summary...

Page 106: ...n the WFR User Guide index see How to generate a Drill Down Report How to use filter columns and buttons Step B Modify the report view to only display top 10 site records 1 Now to only display the top...

Page 107: ...C Export the report view in the PDF output format 1 To export the current report view in the PDF format at the top of the report view click Export Report to open the Export Drill Down Report pop up wi...

Page 108: ...unt the default selection in the Modify Report pop up window 3 Print or save the PDF file using available tools or icons in the PDF file window or close the PDF file In the WFR User Guide index see Ho...

Page 109: ...the report view to open the Save Custom Report pop up window Note that this window is populated with specifications used in the current report view 2 For this exercise make entries in the following f...

Page 110: ...run Now that you ve saved the report you must schedule a time for the report to run 1 When clicking Save and Schedule an alert box opens to let you know the Custom Report has been saved 2 Click OK to...

Page 111: ...the WFR User Guide index see How to schedule a report to run You have now learned how to save a report and schedule a recurring event for running this report Reports created for a variety of purposes...

Page 112: ...ck Add In the WFR User Guide index see How to add a category group in the Web Client Step B Run a report for a specified category group 1 To create a report for category group choose Custom Reports fr...

Page 113: ...n clicking Apply Filter for results 7 Select the user s from the results list box and then click Add to Individuals to include the user s in the Group Definitions list box for the user group In the WF...

Page 114: ...s option choose Custom Reports from the left panel select Custom Report Wizard and then specify Specific User Detail by Page Object Click the Next button choose the User Group name and then click the...

Page 115: ...box In the ER Web Client user interface the following alert pop up box opens when navigating to Settings Server Statistics and accessing the ER Server Informa tion window Click OK to close this alert...

Page 116: ...Window In the ER Server Information window the note Evaluation Mode Enabled displays above the ER Activity frame To the right of this note the Server Info button displays When this button is clicked...

Page 117: ...network activity on LAN2 The LED is a steady green with link connectivity and unlit if there with no link connectivity NIC1 icon A flashing green LED indicates network activity on on LAN1 The LED is...

Page 118: ...Series Unit In addition to executing functions listed in the LCD panel menu the keypad on the front of the server is also used for performing basic server functions Boot up Depress and hold the check...

Page 119: ...ronment This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instruction manual may cause harmful interference to radio communicati...

Page 120: ...A11 2004 EMC EN55022 2006 A1 2007 EN55024 1998 A2 2003 IEC CISPR 22 2008 IEC CISPR 24 1997 A1 2001 A2 2002 EN61000 3 2 2006 EN61000 3 3 2008 CFR47 Part 15 Subpart B 2009 Product Name s Security Applia...

Page 121: ...77 Custom Category blocked 67 custom category group 63 104 Custom Lock Block Warn X Strikes Quota pages 66 custom user group 63 105 Customize an M86 Supplied Category 77 D Detail Drill Down Report 96...

Page 122: ...ount bypass 67 Override Accounts 79 P P2P patterns 70 Pass Allow 78 Pattern detection bypass 79 ping the SR 35 Power Supply Precautions 11 Proxy Patterns 68 Q Quick Start menu 21 R Rack Setup Precauti...

Page 123: ...1 Summary Drill Down Report 94 95 96 97 100 101 T TAR GUI Wizard User 24 31 Threats Liabilities 65 Time Based Profiles 69 76 Time Quota Hit Quota 69 76 U UL 111 URL exceptions 78 URL Keywords 66 73 us...

Page 124: ...INDEX 116 M86 SECURITY INSTALLATION GUIDE...

Page 125: ......

Page 126: ...M86 Security Corporate Headquarters USA 828 West Taft Avenue Orange CA 92865 4232 Tel 714 282 6111 or 888 786 7999 Fax 714 282 6116 Sales Technical Support 714 282 6117 General Office...

Reviews: