Cisco Cisco Web Security Appliance S670 사용자 가이드

다운로드
페이지 784
 
8-5
Cisco IronPort AsyncOS 7.0 for Web User Guide
OL-23079-01
Chapter 8      Access Policies
Evaluating Access Policy Group Membership
  •
Advanced options. You can configure several advanced options for Access 
Policy group membership. Some options (such as proxy port and URL 
category) can also be defined within the Identity. When an advanced option 
is configured in the Identity, it is not configurable in the Access Policy group 
level.
The information in this section gives an overview of how the Web Proxy matches 
client requests to Access Policy groups. For more details about exactly how the 
Web Proxy matches client requests, see 
The Web Proxy sequentially reads through each policy group in the policies table. 
It compares the client request status to the membership criteria of the first policy 
group. If they match, the Web Proxy applies the policy settings of that policy 
group.
If they do not match, the Web Proxy compares the client request to the next policy 
group. It continues this process until it matches the client request to a user defined 
policy group. If it does not match a user defined policy group, it matches the 
global policy group. When the Web Proxy matches the client request to a policy 
group or the global policy group, it applies the policy settings of that policy group.
Matching Client Requests to Access Policy Groups
 shows how the Web Proxy evaluates a client request against 
the Access Policy groups.