Cisco Cisco Web Security Appliance S670 ユーザーガイド
5-33
Cisco IronPort AsyncOS 7.1 for Web User Guide
OL-23207-01
Chapter 5 Web Proxy Services
Advanced Proxy Configuration
Enter maximum idle
timeout for User
Acknowledgement based
on IP Address (in
seconds):
timeout for User
Acknowledgement based
on IP Address (in
seconds):
30 -
2678400
2678400
14400
No
Maximum idle timeout for User
Acknowledgement based on IP
Address. From 30 seconds to one
month (2678400).
Acknowledgement based on IP
Address. From 30 seconds to one
month (2678400).
Should the Group
Membership attribute be
used for directory
lookups in the Web UI
(when it is not used,
empty groups and groups
with different
membership attributes
will be displayed)?
Membership attribute be
used for directory
lookups in the Web UI
(when it is not used,
empty groups and groups
with different
membership attributes
will be displayed)?
Yes, No
(Boolean)
No
No
Choose whether or not AsyncOS
should use the group membership
attribute when doing a directory
lookup.
should use the group membership
attribute when doing a directory
lookup.
If you do not want to display
empty authentication groups and
fetch groups whose group
membership attribute is different,
choose Yes.
empty authentication groups and
fetch groups whose group
membership attribute is different,
choose Yes.
Would you like to allow
case insensitive
username matching in
policies?
case insensitive
username matching in
policies?
Yes, No
(Boolean)
Yes
Yes
Choose whether or not the Web
Proxy should ignore case when
matching user names against the
policy groups.
Proxy should ignore case when
matching user names against the
policy groups.
Would you like to allow
wild card matching with
the character * for LDAP
group names?
wild card matching with
the character * for LDAP
group names?
Yes, No
(Boolean)
Yes
Yes
Choose whether or not to match
an asterisk as a wildcard in LDAP
group filters.
an asterisk as a wildcard in LDAP
group filters.
When this option is disabled,
using an asterisk (*) in the group
filters for LDAP servers works as
a literal string.
using an asterisk (*) in the group
filters for LDAP servers works as
a literal string.
Table 5-4
advancedproxyconfig CLI Command—Authentication Options (continued)
Option
Valid
Values
Values
Default
Value
Value
Web Proxy
Must Restart
Must Restart
Description