Cisco Cisco Web Security Appliance S670 User Guide
![Cisco](https://files.manualsbrain.com/attachments/7380d0050044647c30f5c24bbbf5d0c0b6d9bb84/common/fit/150/50/faa183d287233c52228cfea3dbc2a127fe780f60564fcb0955d9c3d1cd23/brand_logo.png)
140
I R O N P O R T A S Y N C O S 6 . 3 F O R W E B U S E R G U I D E
For more information, see “Allowing Guest Access to Users Who Fail Authentication” on
page 135.
page 135.
10. Optionally, expand the Advanced section to define additional membership requirements.
11. To define Identity group membership by any of the advanced options, click the link for the
advanced option and configure the option on the page that appears.
Table 7-2 describes the advanced options you can configure for Identity groups.
Table 7-2 Identity Group Advanced Options
Advanced Option
Description
Proxy Ports
To define policy group membership by the proxy port used to
access the Web Proxy, enter one or more port numbers in the
Proxy Ports field. Separate multiple ports with commas.
For explicit forward connections, this is the port configured in the
browser. For transparent connections, this is the same as the
destination port. You might want to define policy group
membership on the proxy port if you have one set of clients
configured to explicitly forward requests on one port, and another
set of clients configured to explicitly forward requests on a
different port.
Note: IronPort recommends only defining policy group
membership by the proxy port when the appliance is deployed in
explicit forward mode, or when clients explicitly forward requests
to the appliance. When you define policy group membership by
the proxy port when clients requests get transparently redirected to
the appliance, some requests might be denied.
access the Web Proxy, enter one or more port numbers in the
Proxy Ports field. Separate multiple ports with commas.
For explicit forward connections, this is the port configured in the
browser. For transparent connections, this is the same as the
destination port. You might want to define policy group
membership on the proxy port if you have one set of clients
configured to explicitly forward requests on one port, and another
set of clients configured to explicitly forward requests on a
different port.
Note: IronPort recommends only defining policy group
membership by the proxy port when the appliance is deployed in
explicit forward mode, or when clients explicitly forward requests
to the appliance. When you define policy group membership by
the proxy port when clients requests get transparently redirected to
the appliance, some requests might be denied.
URL Categories
Choose the user defined or predefined URL categories.
Membership for both user defined and predefined URL categories
are excluded by default, meaning the Web Proxy ignores all
categories unless they are selected in the Add column.
Membership for both user defined and predefined URL categories
are excluded by default, meaning the Web Proxy ignores all
categories unless they are selected in the Add column.