Cisco Cisco Web Security Appliance S690 User Guide

Page of 455
 
15-2
AsyncOS 8.7 for Cisco Web Security Appliances User Guide
 
Chapter 15      Managing Access to Web Applications
  Enabling the AVC Engine
Enabling the AVC Engine
Enable the AVC engine when you enable .
Step 1
Choose Security Services > Acceptable Use Controls.
Step 2
Click Edit Global Settings.
Step 3
Be sure Enable  is checked.
Step 4
In the Acceptable Use Controls Service panel, select Cisco Web Usage Controls, and then select Enable 
Application Visibility and Control
.
Step 5
Submit and Commit Changes.
Note
You can view the AVC engine scanning activity in the Application Visibility report on the Reporting > 
Application Visibility
 page.
Related topics
AVC Engine Updates and Default Actions 
AsyncOS periodically queries the update servers for new updates to all security service components, 
including the AVC engine. AVC engine updates can include support for new application types and 
applications, as well as updated support for existing applications if any application behaviors change. 
By updating the AVC engine between AsyncOS version updates, the Web Security appliance remains 
flexible without requiring a server upgrade.
AsyncOS for Web assigns the following default actions for the Global Access Policy:
New Application Types default to Monitor.
New application behaviors, such as block file transfer within a particular application; defaults 
to Monitor.
New applications for an existing application type default to the Application Type’s default.
Note
In the Global Access Policy, you can set the default action for each Application Type, so new 
applications introduced in an AVC engine update automatically inherit the specified default action. See 
.
User Experience with Blocked Requests
When the AVC engine blocks a transaction, the Web Proxy sends a block page to the end user. However, 
not all Websites display the block page to the end user; many Websites display dynamic content using 
JavaScript instead of a static Webpage and are not likely to display the block page. Users are still properly 
blocked from downloading malicious data, but they may not always be informed of this by the Website.