Dell SMA 200 Administration Manual page 284

Table of Contents

Advertisement

transported only in HTTPS connections. Both together add a strong layer of security for the server-side
cookies.
6
For Client Cookies, select Allow if an application on the portal needs all of the client cookies. When
disabled, client-side cookies are not allowed to be sent to the backend systems. This option does not
affect server-side cookies.
7
For the Exclusion List, select Enabled to display additional fields for configuration.
8
To enter a custom cookie name and path to the Exclusion List, click in the Cookie Name field to type in
the name of the cookie, and click in the Cookie Path field to type in the path. Then click > Add.
9
To add one or more already-detected cookies to the Exclusion List, select the desired cookies in the
Detected Cookies list, holding the Ctrl key while clicking multiple cookies, and then click < Add to add
them to the Exclusion List.
10 To remove cookies from the Exclusion List, select the cookies to be removed and then click Remove.
11 To clear the Detected Cookies list, click Clear.
12 When finished, click Accept.
Configuring Web Site Cloaking
Under Web Site Cloaking, you can filter out headers in response messages that could provide information to
clients about the backend Web server that could possibly be used to find a vulnerability.
To configure Web site cloaking:
1
Expand the Web Site Cloaking section.
2
In the Block Response Header fields, type the server host name into the first field and type the header
name into the second field, then click Add.
For example, if you set the host name to "webmail.xyz.com" and the header name to "X-OWA-version,"
headers with the name "X-OWA-version" from host "webmail.xyz.com" is blocked. In general, listed
headers are not sent to the client if an HTTP/HTTPS bookmark or off-loaded application is used to access
a listed Web server.
To block a certain header from all hosts, set the host name to an asterisk (*). You can add up to 64
host/header pairs. In the HTTP protocol, response headers are not case-sensitive.
NOTE:
Blocking does not occur for headers such as Content-Type that are critical to the
HTTP protocol.
3
To remove a host/header pair from the list to be blocked, select the pair in the text box and then click
Remove.
Dell SonicWALL Secure Mobile Access 8.5
Administration Guide
284

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sma 400Sra 1600Sra 4600Sma 500v

Table of Contents