S W G U s e r G u i d e
41
Chapter 5: Implementing Identification Policy
Edit
.
• To add a new condition to a rule:
i. Right‐click the rule and choose
Add
Condition
.
The main window displays the Condition Definition screen.
ii. In the
Condition
Name
field
, select the type of condition in the drop‐down list. The list
contains the following Condition types:
•
Destination
Port
Range
— distinguishes client application connecting to M86 SWG
by the target destination port. The default rule allows the administrator to exclude a list
of Port ranges.
•
Header
Fields
— limits direct internet access according to header name and value.
•
IP
Range
— limits direct internet access according to IP ranges.
•
Location
— limits direct internet access according to location of the scanning server
both for Cloud or Local.
•
URL
Lists
— limits direct internet access according to the target URL.
For any selected condition type, the window displays an appropriate checkbox list.
For detailed information on condition types and the particular items in a condition list, see the
Management
Console
Reference
Guide
.
b. Click
Save
.
8. Set the defined policy as the Identification Policy, as follows:
a. Select
Administration
Æ
System
Settings
Æ
M86
Devices
.
b. In the configuration tree at the right, choose
Scanning
Server
Æ
General
.
c. In the main screen at the right, click the
Device
Policy
tab, and then click
Edit
.
d. In the
Identification
Policy
field, select the policy.
e. Click
Save
.
9. If you are implementing an Authentication‐type Identification policy, and should configure
device Authentication parameters (for example, if and how long to retain Authentication data).
For instructions, see
Chapter 6: Implementing Authentication
.
10. If you are ready to distribute and implement the changes in your system devices, click
.
11. Test the identification policy by having a user browse, and then check the log to ensure that the
Identification policy has been enforced.
Defining an Active Directory
NOTE:
This
procedure
needs
to
be
performed
only
if
you
are
defining
an
Authentication
type
policy
as
your
Identification
Policy.
In
this
case,
it
should
be
performed
before
defining
the
Identification
Policy.
1. Select
Users
Æ
Authentication
Directories
Æ
Active
Directories
.
2. In the configuration tree at the right, right click on the
Active
Directory
root branch, and click
Add
Site
.
3. Define the Active Directory as follows:
a. Assign a name to the Active Directory.