Cisco Cisco Web Security Appliance S170 Guía Del Usuario
5-23
Cisco IronPort AsyncOS 7.7 for Web User Guide
Chapter 5 Web Proxy Services
Advanced Proxy Configuration
Authentication Options
advancedproxyconfig
CLI command.
Table 5-4
advancedproxyconfig CLI Command—Authentication Options
Option
Valid
Values
Values
Default
Value
Value
Web Proxy
Must Restart
Must Restart
Description
When would you like to
forward authorization
request headers to a
parent proxy?
forward authorization
request headers to a
parent proxy?
Never,
Always,
Only if not
used by
the WSA
Always,
Only if not
used by
the WSA
Never
Yes
This setting determines whether
the Web Proxy includes the
“Proxy-Authorization” header to
upstream servers, including
proxies.
the Web Proxy includes the
“Proxy-Authorization” header to
upstream servers, including
proxies.
Enter the Proxy
Authorization Realm to
be displayed in the end
user authentication
dialog
Authorization Realm to
be displayed in the end
user authentication
dialog
String
“Cisco
IronPort
Web
Security
Appliance”
IronPort
Web
Security
Appliance”
No
Proxy Authorization Realm
displayed in the End User
Authentication dialog.
displayed in the End User
Authentication dialog.
Would you like to log the
username that appears in
the request URI?
username that appears in
the request URI?
Yes, No
(Boolean)
No
No
If enabled, ‘<username>:xxxxx’
is logged i.e the username is
displayed and the password is
represented as a string, ‘xxxxx’.
If disabled, both username and
password are stripped. Note that
the actual password is never
displayed regardless of the value
of this variable.
is logged i.e the username is
displayed and the password is
represented as a string, ‘xxxxx’.
If disabled, both username and
password are stripped. Note that
the actual password is never
displayed regardless of the value
of this variable.
Should the Group
Membership attribute be
used for directory
lookups in the Web UI
(when it is not used,
empty groups and groups
with different
membership attributes
will be displayed)?
Membership attribute be
used for directory
lookups in the Web UI
(when it is not used,
empty groups and groups
with different
membership attributes
will be displayed)?
Yes, No
(Boolean)
No
No
Choose whether or not AsyncOS
should use the group membership
attribute when doing a directory
lookup.
should use the group membership
attribute when doing a directory
lookup.
If you do not want to display
empty authentication groups and
fetch groups whose group
membership attribute is different,
choose Yes.
empty authentication groups and
fetch groups whose group
membership attribute is different,
choose Yes.
Would you like to use
advanced Active
Directory connectivity
checks?
advanced Active
Directory connectivity
checks?
Yes, No
(Boolean)
No
No
Choose whether or not the Web
Proxy should automatically
restart the internal authentication
process that communicates with
Active Directory servers when it
becomes unresponsive, but is still
running.
Proxy should automatically
restart the internal authentication
process that communicates with
Active Directory servers when it
becomes unresponsive, but is still
running.
Would you like to allow
case insensitive
username matching in
policies?
case insensitive
username matching in
policies?
Yes, No
(Boolean)
Yes
Yes
Choose whether or not the Web
Proxy should ignore case when
matching user names against the
policy groups.
Proxy should ignore case when
matching user names against the
policy groups.