You should consult with a professional where appropriate. Neither the author nor Trustwave shall be liable for any loss of profit or any commercial damages, including but not limited to direct, indirect, special, incidental, consequential, or other damages.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 Formatting Conventions This manual uses the following formatting conventions to denote specific information. Format and Meaning Symbols Blue Underline A blue underline indicates a Web site or email address. Bold...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 1 Web Filter Appliance Introduction Thank you for choosing to install and evaluate the Trustwave Web Filter appliance. Trustwave’s Web Filter tracks each user’s online activity, and can be configured to block specific Web sites, service ports, and...
Trustwave solutions engineer or technical support representative. For technical assistance or warranty repair, please visit http://www.trustwave.com/support/. 2.1 Trustwave Technical Support Call Procedures When calling Trustwave regarding a problem, please provide the representative the following information: • Your contact information.
1 bezel to be installed on the front of the chassis • 1 set of rack mounting rails • For 300 series models, the following items are also included in the carton: • 1 power adapter with power cord •...
3.2.1.1 Set Top Applications If you have a 300 series server you do not wish to rack mount, apply the pressure sensitive feet (that came with the server) to the bottom corners of the unit, and then place the unit in a location that meets server site selection criteria.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3.3 Rack Mount the Server 3.3.1 Rack Setup Precautions Warning: Before rack mounting the server, the physical environment should be set up to safely accommodate the server. Be sure that: •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3. Securely attach the slide to the chassis with two M4 flat head screws. 4. Repeat steps 1-3 to install the left inner slide to the left side of the chassis.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3.3.2.5 Install the Chassis into the Rack 1. Push the inner slides, which are attached to the chassis, into the grooves of the outer slide assemblies that are installed in the rack as shown below: 2.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3.3.3 Rack Mount Instructions for 700 Series Servers 3.3.3.1 Rack Setup Suggestions • Determine the placement of each component in the rack before you install the rails. • Install the heaviest server components on the bottom of the rack first, and then work up.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3. Secure the chassis with 2 screws as illustrated. 4. Repeat steps 1-3 for the other inner rail extension. 3.3.3.4 Install the Outer Rails 1. Attach the short bracket to the outside of the long bracket. You must align the pins with the slides.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3.3.3.5 Install the Server into the Rack 1. Confirm that chassis includes the inner rails (A) and rail extensions (B). Also, confirm that the outer rails (C) are installed on the rack.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3.3.3.6 Install the Server into a Telco Rack If you are installing the server into a Telco type rack, follow the directions given on the previous pages for rack installation. The only difference in the installation procedure will be the positioning of the rack brackets to the rack.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3.3.4 Install the Bezel on the 500 and 700 Series Chassis After rack mounting a 500 or 700 series server, the bezel should be installed on the front end of the chassis.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. Note the short pair of end pins on the left side, and the longer pair of fixed pins on the inside top towards the middle. 3. Note the end pin holes on the inside of the U-shaped, aluminum rail handles on both ends of the chassis rails.
Caution: If the server is used in a manner not specified by the manufacturer, the protection provided by the server may be impaired. Caution: Trustwave is not responsible for regulatory compliance of any server that has been modified. Altering the server’s enclosure in any way other than the installation operations specified in this document may invalidate the server’s safety certifications.
• Do not expose the server to rain or use near water. If liquids of any kind should leak into the chassis, power down the server, unplug it, and contact Trustwave technical support. • Disconnect power from the server before cleaning the unit. Do not use liquid or aerosol cleaners.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3.5.4 Motherboard Battery Precautions Warning: The battery on the motherboard should not be replaced without following instructions provided by the manufacturer. Only qualified service personnel should replace batteries. The battery contains energy and, as with all batteries, a malfunction can cause heat, smoke, or fire, release toxic materials, or cause burns.
Go to Section 4.2 to execute Quick Start Setup Procedures. Note: • For 300 series models, the power adapter supplied with the power cord must also be used • Windows XP includes HyperTerminal. If using a more recent version of Windows, please be sure HyperTerminal or an equivalent terminal emulator program is installed on your machine.
1. Using the serial port null modem cable (and USB DB9 serial adapter, if necessary), connect the laptop to the rear of the chassis. Figure 1: Rear of 300 series chassis with serial port identified Figure 2: Portion of 500 series chassis rear with serial port identified Figure 3: Portion of 700 series chassis rear with serial port identified 2.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3. Go to the LCD panel on the front of the chassis, and press down the green check mark key for three seconds. 4. When the LCD panel displays a message that indicates the Web Filter is running, proceed to the following set of instructions: •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 4.2.4 Login screen The login screen displays after powering on the Web Filter using a monitor and keyboard, or after creating a serial (HyperTerminal) session. Note: If using a HyperTerminal session, the login screen will display with black text on a white back- ground.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 4.2.6 Quick Start menu: administration menu 1. At the Press the number of your selection prompt, press 2 to select the “Quick Start Setup” process. • The Quick Start menu takes you to the following configuration screens to make entries: •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. Select a filter mode (Invisible, Router, Firewall, or Bridge) using up-arrow and down-arrow keys. Press Y when you have selected the appropriate mode, or press Esc to cancel this change.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. At the Enter default gateway IP prompt, type in the gateway IP address and press Enter. 3. Press Y to confirm, or press any other key to cancel this change.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. At the Press Y to continue prompt, press Y to continue, or press any other key to cancel the reset process. Caution: This option will delete all configuration settings and profiles stored on the server, and revert the server back to the original software version on the hard drive.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 4.2.7 System Status screen The System Status screen displays the following information: • Serial Number assigned to the chassis • Operation Mode for the Web FIlter specified in screen 3 (Change filtering mode) •...
The keypad includes the following keys: • On a 300 series model: Up arrow, down arrow, left arrow, right arrow, check mark, and “X” keys. • On a 500 or 700 series model: Up, down, left, right, CANCEL, and ENTER keys.
(arrow) keys to navigate the menu. After making your menu selection, press the check mark / ENTER key to accept your selection. 4.3.2 Trustwave menu When the Trustwave menu option is selected from the LCD Menu tree, the following menu items display in the panel, the entire list which is viewable by using the navigation keys: •...
6. Press the check mark / ENTER key to accept your entry and to return to the previous screen. 7. Press the “X” / CANCEL key to return to the Trustwave menu. Go to Section 4.3.2.4.
6. Press the check mark / ENTER key to accept your entry and to return to the previous screen. 7. Press the “X” / CANCEL key to return to the Trustwave menu. 4.3.2.4 Gateway When the Gateway option is selected, the Gateway screen displays with the Configure Gateway IP menu item.
3. Press the check mark / ENTER key to accept your entry and to return to the previous screen. 4. Press the “X” / CANCEL key to return to the Trustwave menu. 4.3.2.6 Host Name When the Host Name option is selected, the Host Name screen displays with the Configure Hostname menu item.
• No, cancel reboot - This selection returns you to the previous screen. 2. Press the “X” / CANCEL key to return to the Trustwave menu. 4.3.2.8.5 Shutdown When the Shutdown option is selected, the Shutdown screen displays with two menu items.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 • heartbeat feature enabled (populated field) • heartbeat feature disabled (empty field) • check for a heartbeat now (blinking heartbeat symbol displayed in the line above) 2. After making your selection, press the “X” / CANCEL key to return to the previous screen.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 Figure 4: Rear of 300 series chassis with LAN ports identified Figure 5: Portion of 500 series chassis rear with LAN ports identified Figure 6: Portion of 700 series chassis rear with LAN ports identified 2.
Reboot option on the LCD panel (as described in Section 4.3). 4.4.2.2 Bridge mode without bypass card installed If you plan to use Bridge mode without a bypass card (for instance, with model 300 appliances), you must connect the cables to the correct ports.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 4. Plug the other end of this cable into a port on the network router, firewall, or other device that provides outbound Internet access for your network. Tip: Usually this will be the port that was previously used by the other end of the cable you unplugged from the switch 5.
Web Filter. • If still unsuccessful, contact a Trustwave solutions engineer or technical support representative. 4.6 Log in, Generate SSL Certificate In this step, you will log in to the Web Filter and generate a self-signed certificate to ensure secure exchanges between the appliance and your browser.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. Click LOGIN to display the Web Filter Admin console Welcome window: 4.6.2 Generate SSL Certificate 1. Navigate to System | UI SSL Certificate to open the SSL Certificate window: 2.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 • If using an IE browser, proceed to Section 4.6.3: IE Security Certificate Installation Procedures. • If using a Firefox, Safari, or Chrome browser, proceed to Section 4.7: Test Filtering or the Mobile Security Client Connection.
Page 57
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5. Click Next > to display the Certificate Store page: 6. Choose the option “Place all certificates in the following store” and then click Browse... to open the Select Certificate Store box: 7.
Page 58
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 9. Click Finish to close the wizard and to open the Security Warning dialog box asking if you wish to install the certificate: 10. Click Yes to install the certificate and to close the dialog box. When the certificate is installed, the alert window opens to inform you the certificate installation process has been completed.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 g. Choose “Trusted Root Certification Authorities” and then click OK to close the box. h. Click Next > to display the last page of the wizard. Click Finish to close the wizard and to open the Security Warning dialog box asking if you wish to install the certificate.
Page 60
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. Double-click “hosts” to open a window asking which program you wish to use to open the file. Double- click “Notepad” or “TextPad” to launch the hosts file using that selected program: 3.
• http://testsite.marshal.com 2. You should receive a block page for each URL tested. If you do not, contact a Trustwave solutions engineer or technical support representative. 4.7.2 Test the Mobile Security Client Connection If the Web Filter has been set up to use the Mobile mode, you should verify that the Mobile Security Client can reach the Web Filter.
2. The connections should be blocked, and the block pages served by the Web Filter should display in the browser’s Address field. If you do not receive a block page for each tested URL, contact a Trustwave solutions engineer or technical support representative.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. After reading through the online End User License Agreement, click Accept to go to Step 2 of the activation process: 3. Enter your activation code from the email. 4. Click Activate to activate the Web Filter. You should receive a confirmation page informing you that the Web Filter has been activated.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. From the navigation panel to the left, click Updates and select Manual Update from the menu: 3. In the Manual Update to Trustwave Supplied Categories window, click the radio button corresponding to Full URL Library Update.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 Note: You will be notified in the log when the library has been completely updated by the message: “Full URL Library Update has completed.” If this message does not yet display, click View Log again to view the latest information.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5 Best Filtering Practices This collection of setup and usage scenarios is designed to help you understand and use basic tools in the Web Filter console for configuring the user interface and creating filtering profiles for users in your network.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1 Threat Class Groups Trustwave’s filtering library currently consists of 104 library filtering categories, each placed in one of the 20 filtering category groups defined in the interface: Adult Content, Bandwidth, Business/Investments,...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.1 Threats/Liabilities 5.1.1.1 Category block Block categories that threaten your network/organization. In pertinent profiles, block access to the Security category group and other categories containing content that threaten your organization.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.1.3 X-Strike on blocked categories Lock out users from workstations after “X” number of attempts are made to access content that could endanger your network/organization. Enable and configure the X Strikes Blocking feature, specifying categories that threaten your organization.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.1.6 Search Engine Keywords Block access to network-endangering content via search engine keywords. In pertinent library categories, enter SE keywords to be blocked. Block these categories in applicable profiles. To set up Search Engine Keywords to be blocked, go to: •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.1.9 Override Account bypass Use an Override Account to grant a user access to categories blocked at the root level. To grant designated users access to globally-blocked categories, set up an Override Account at the Global Group level, or enable the option to allow the Minimum Filtering Level to be bypassed with an Override Account, and then set up the Override Account at the group level.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.1.11 Proxy Patterns Prevent users from using proxy patterns to bypass the Internet filter. Enable Pattern Blocking for all users. In the profile, block Security | Web-based Proxies/Anonymizers. To set up the proxy pattern blocking feature and apply it to profiles, go to: •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.2 Bandwidth/Productivity 5.1.2.1 Time Quota/Hit Quota Limit time spent in PASSED categories to prevent excessive bandwidth usage and increase productivity. Enable the Quota Settings feature, and configure the Seconds Per Hit. Set up pertinent categories in the user’s profile with quotas so the user is notified and then locked out of those categories...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.2.4 Warn option with low filter settings Warn users before they access unacceptable content that their Internet activities are logged. Set HTTPS filtering at the “low” level, and then configure the number of minutes for the interval the warning page will re-display for any user who attempts to access content deemed unacceptable.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.2.6 P2P patterns Block P2P services. Enable Pattern Blocking for all users. In the profile, block Bandwidth | Peer-to- peer/File Sharing category. To block P2P services, go to: • SYSTEM: System | Control | Filter window •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.2.9 Streaming Media patterns Block streaming media patterns. Enable Pattern Blocking for all users. In the profile, block Bandwidth | Streaming Media category. To block streaming media patterns, go to: •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.2.12 Category block Block the Bandwidth category. Set the Bandwidth category to be blocked in pertinent profiles. To block the Bandwidth category, go to: • POLICY: Policy | IP | member | member profile | Category tab...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.2.15 URL Keywords Block specific URL keywords to restrict access to bandwidth-consumptive categories. In pertinent library categories, enter SE keywords to be blocked. Block these categories in the profile. To set up and block URL keywords in a profile, go to: •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.3 General/Productivity 5.1.3.1 Warn Feature with higher thresholds Warn users before they access unacceptable content. Set HTTPS filtering at the “high” level to block certificates that may be questionable. Configure Warning settings. In the end user’s profile, apply the warn option to pertinent categories.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 or POLICY: Policy | Global Group | Global Group Profile | Category tab (Warn column), and Filter Options tab (X Strikes Blocking enabled) In the Web Filter Administrator Guide index, see: •...
5.1.3.6 Customize a Trustwave Supplied Category Include region-specific content in a Trustwave Supplied category. Add/delete content to/from an existing Trustwave Supplied Category that only includes content pertinent to your organization or region that should be blocked. Apply this category to a profile.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.3.7 Local category adds/deletes Include region-specific content in a Custom category. Set up a custom category that only includes content pertinent to your organization or region that should be blocked. Apply this category to a profile.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.4 Pass/Allow 5.1.4.1 Always Allow Custom Category Create a white list custom category. Set up an Always Allow category and add all URLs deemed acceptable. Apply this category to all pertinent profiles. Please keep in mind that if any library category in this list is set up to be blocked in the Minimum Filtering Level, the Minimum Filtering Level setting will override the entry in the Always Allow custom category.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.4.3 IP exceptions Use Exception URLs to grant individuals access to IPs blocked by the Minimum Filtering Level. Enable the option to bypass the Minimum Filtering Level using exception URLs. Enter the exception Internet/intranet IP addresses in the applicable profile.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 5.1.4.5 Pattern detection bypass Allow specific IP addresses to always bypass filtering. Block all patterns with the exception of a list of specific IP addresses that should always bypass the filter.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 6 LED Indicators and Buttons 6.1 Front Control Panels on 500 and 700 Series Units Control panel buttons, icons, and LED indicators display on the right side of the 500 and 700 series model front panel.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 Table 1: Buttons and icons Item Explanation Power (icon) – The LED is unlit when the server is turned off. A steady green LED indicates power is being supplied to the unit’s power supplies.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 7.1.6 EC Declaration of Conformity 7.1.6.1 European Community Directives Requirement (CE) Manufacturer’s Name: M86 Security Manufacturer’s Address: 828 W. Taft Avenue Orange, CA 92865 Application of Council Directive(s): Low Voltage •...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 Appendices Appendix A: HyperTerminal setup procedures If you want to use a serial port connection for the initial configuration of the Web Filter, you can use the following procedures to launch HyperTerminal and connect to the Web Filter.
Page 92
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3. At the Connect using field, select the COM port assigned to the serial port on the laptop (probably “COM1”), and then click OK to open the Properties dialog box, displaying the Port Settings tab: 4.
Page 93
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 6. In the HyperTerminal session window, go to File | Properties to open the Properties dialog box, displaying the Connect To and Settings tabs: 7. Click the Settings tab, and at the Emulation menu select “VT100”.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 Appendix B: Accepting Security Certificates When you connect to the Web Filter, you may need to accept a security certificate exception. This is a normal behavior for the certificate used by this product. This appendix provides detailed walk-throughs of the procedure in several supported web browsers.
Page 95
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 3. Clicking Add Exception opens the Add Security Exception window: 4. In the Add Security Exception window, click Get Certificate and wait a few seconds until the security certificate is obtained by the server.
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 B.2 Temporarily Accept the Security Certificate in IE If using an IE browser, in the page “There is a problem with this website's security certificate.”, click Continue to this website (not recommended):...
Trustwave Web Filter - Appliance Installation Guide - Version 5.1.00 2. Click the “Always trust...” check box and then click Continue: 3. You will be prompted to enter your password in order to install the certificate. B.4 Accept the Security Certificate in Chrome If using a Chrome browser, in the page “This is probably not the site you are looking for!”...
Page 104
About Trustwave® Trustwave is a leading provider of compliance, Web, application, network and data security solutions delivered through the cloud, managed security services, software and appliances. For organizations faced with today's challenging data security and compliance environment, Trustwave provides a unique approach with comprehensive solutions that include its TrustKeeper® portal and other proprietary security solutions. — Trustwave has helped hundreds of thousands of organizations ranging from Fortune — 500 businesses and large financial institutions to small and medium‐sized retailers manage compliance and secure their network infrastructures, data communications and critical information assets. Trustwave is headquartered in Chicago with offices visit https://www.trustwave.com. worldwide. For more information, ...
Need help?
Do you have a question about the 300 and is the answer not in the manual?
Questions and answers