Руководство Пользователя для Cisco Cisco Content Security Management Appliance M160

Скачать
Страница из 437
 
9-9
AsyncOS 8.1 for Cisco Content Security Management User Guide
 
Chapter 9      Managing Web Security Appliances
SMA-Specific Differences when Configuring Features in Configuration Masters 
When you configure a feature in a Configuration Master, note the following differences from configuring 
the same feature directly on the Web Security appliance. 
Tip for Working with Identities in Configuration Masters 
When creating an Identity on the Security Management appliance, you have the option of making it 
apply only to specific appliances. So for example, if you purchase a Security Management appliance and 
want to preserve the existing Web Security appliance configurations and the policies that were created 
for each Web Security appliance, you must load one file into the machine, and then add policies from 
other machines by hand.
One way to accomplish this is to make a set of Identities for each appliance, then have policies which 
refer to those Identities. When the Security Management appliance publishes the configuration, those 
Identities and the policies which refer to them will automatically be removed and disabled. Using this 
method, you do not have to configure anything manually. This is essentially a ‘per-appliance’ identity.
Table 9-1
Feature Configuration: Differences between Configuration Master and Web Security Appliance 
Feature or Page 
Details 
All features, especially new 
features in each release 
For each feature that you configure in a Configuration Master, you must enable the 
feature in the Security Management appliance under Web > Utilities > Security Services 
Display. For more information, see 
Identities 
  •
See 
  •
If you have realms on different Web Security appliances that have the same name 
but different protocols, choose the appropriate scheme for each desired realm in the 
Configuration Master. 
  •
The Identify Users Transparently option when adding or editing an Identity is 
available when a Web Security appliance with an authentication realm that supports 
transparent user identification has been added as a managed appliance. 
This feature was introduced in Configuration Master 7.5. 
SaaS Policies 
The authentication option “Prompt SaaS users who have been discovered by transparent 
user identification” is available only when a Web Security appliance with an 
authentication realm that supports transparent user identification has been added as a 
managed appliance. 
Access Policies > Edit Group 
 
When you configure the Identities and Users option in the Policy Member Definition 
section, the following applies if you use external directory servers: 
When you search for groups on the Edit Group page, only the first 500 matching results 
are displayed. If you do not see the desired group, you can add it to the “Authorized 
Groups” list by entering it in the Directory search field and clicking the "Add" button.  
Access Policies > Web Reputation 
and Anti-Malware Settings 
Options available on this page depend on whether Adaptive Scanning is enabled for the 
relevant configuration master. Check this setting in Web > Utilities > Security Services 
Display. 
This feature was introduced in Configuration Master 7.5.