Cisco Cisco Web Security Appliance S170 Guida Utente

Pagina di 486
 
3-6
AsyncOS 10.0 for Cisco Web Security Appliances User Guide
 
Chapter 3      Connect the Appliance to a Cisco Cloud Web Security Proxy
  Preventing Loss of Secure Data
FTP over HTTP is supported in Cloud Connector mode.
HTTPS
The Cloud Connector does not support decryption. It passes HTTPS traffic without decrypting.
Because the Cloud Connector does not support decryption, AsyncOS generally does not have access to 
information in the client headers of HTTPS traffic. Therefore, AsyncOS generally cannot enforce 
routing policies that rely on information in encrypted headers. This is always the case for transparent 
HTTPS transactions. For example, for transparent HTTPS transactions, AsyncOS does not have access 
to the port number in the HTTPS client header and therefore it cannot match a routing policy based on 
port number. In this case, AsyncOS uses the default routing policy.
There are two exceptions for explicit HTTPS transactions. AsyncOS has access to the following 
information for explicit HTTPS transactions:
URL
Destination port number
For explicit HTTPS transactions, it is possible to match a routing policy based on URL or port number.
Preventing Loss of Secure Data
You can integrate the Cloud Connector with external Data Loss Prevention servers through Network 
External DLP Servers
Related Topics
 
Viewing Group and User Names and IP Addresses 
To view the configured group names, user names, and IP addresses, go to whoami.scansafe.net. 
Subscribing to Cloud Connector Logs
The Cloud Connector Logs provides useful information for troubleshooting problems with the Cloud 
Connector, for example, authenticated users and groups, the Cloud header, and the authorization key. 
Step 1
Navigate to System Administration Log Subscriptions.
Step 2
Select Cloud Connector Logs from the Log Type menu.
Step 3
Type a name in the Log Name field.
Step 4
Set the log level.
Step 5
Submit and Commit your changes.
Related Topics