NETGEAR STM150 Appliance Reference Manual page 137

Prosecure web/email security threat management (stm)
Hide thumbs Also See for STM150:
Table of Contents

Advertisement

ProSecure Web/Email Security Threat Management (STM) Appliance Reference Manual
If one of these is not satisfied, a security alert message appears in the browser window (see
Figure
4-16).
Figure 4-16
However, even when a certificate is trusted or still valid, or when the name of a certificate does
match the name of the Web site, a security alert message still appears when a user who is
connected to the STM visits an HTTPS site. The appearance of this security alert message is
expected behavior because the HTTPS client receives a certificate from the STM instead of
directly from the HTTPS server. If you want to prevent this security alert message from appearing,
install a root certificate on the client PC. The root certificate can be downloaded from the STM's
User Portal Login screen (see
Figure 5-7 on page
5-10).
If client authentication is required, the STM might not be able to scan the HTTPS traffic because
of the nature of SSL. SSL has two parts—client and server authentication. HTTPS server
authentication occurs with every HTTPS request, but HTTPS client authentication is not
mandatory, and rarely occurs. Therefore it is of less importance whether the HTTPS request comes
from the STM or from the real HTTPS client.
However, certain HTTPS servers do require HTTPS client certificate authentication for every
HTTPS request. Because of the design of SSL, the HTTPS client must present its own certificate
in this situation rather than using the one from the STM, preventing the STM from scanning the
HTTPS traffic.
You can specify trusted hosts for which the STM bypasses HTTPS traffic scanning. For more
information, see
"Specifying Trusted Hosts" on page
4-41.
Content Filtering and Optimizing Scans
4-39
v1.0, September 2009

Advertisement

Table of Contents
loading

This manual is also suitable for:

Stm300Stm600

Table of Contents