Explicit Proxy - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

Methods
All methods

Explicit proxy

When a proxy is entered in the browser, two modes of authentication are possible:
Standard or Cookie mode
l
This mode is easy to set up thanks to the Explicit HTTP proxy rule creation wizard, offered in the
Filtering module. Two rules are generated – one redirects traffic to the explicit HTTP proxy, and
the other applies the filter policy. Prescriptions with regard to user authentication have to be
stipulated in a rule to be inserted between the two rules that the creation wizard generates, after
the redirection to the HTTP proxy and before authorizing traffic via the Explicit HTTP proxy.
Authentication offered by the browser (HTTP code 407)
l
The feature Proxy-Authorization - HTTP code 407 can be enabled in the advanced properties of
the HTTP protocol module (Proxy tab) accessible via the menu Application protection.
There are however certain restrictions to these modes, as shown in the table below:
Standard mode
Methods Inspections
All
All
methods
inspections
except on
SSL traffic
Filtering by
user
Content
Filtering by user can be applied to HTTP and HTTPS, except for multi-user networks in Cookie
mode (HTTP only).
Explicit mode involves HTTP traffic via the CONNECT method. HTTPS traffic is then encapsulated in
HTTP and the method for sending requests allows setting up a relationship of trust between the
client and the server.
Page 60/448
Single user
Inspections
All inspections
Single user
"Proxy-Authorization" code
407
Methods
Inspections Methods Inspections
LDAP
All
l
inspections
RADIUS
l
except on
Kerberos
l
SSL traffic
SSO Agent
Filtering by
l
user
Δ passwords in
plaintext
(encoded in
base 64)
filtering
can
SNS - USER CONFIGURATION MANUAL V.3
Multi-user objects (Cookie mode)
Methods
All methods
except SSO agent
Multi-user objects
Cookie mode
All
All
methods
inspections
except
except on
SSO
SSL traffic
Filtering by
agent
user (HTTP
only)
only
be
applied
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
AUTHENTICATION
Inspections
All inspections
"Proxy-Authorization" code
407
Methods
Inspections
LDAP
All
l
inspections
RADIUS
l
except on
Kerberos
l
SSL traffic
Filtering by
Δ passwords in
user
plaintext
(encoded in
base 64)   
to
HTTP
traffic.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents