Icap Authentication - McAfee MAP-3300-SWG - Web Security Appliance 3300 Product Manual

Product guide
Table of Contents

Advertisement

Response modification service
Table 155 Option definitions
Option
Service path
Timeouts
Table 156 Option definitions
Option
Definition
Specifies how long the appliance waits to receive data from the ICAP client.
Data timeout
Default value is 60 seconds.
Check connection every Specifies how often the appliance checks that the ICAP client is still connected.
Default value is 20 seconds.

ICAP Authentication

Use this page to specify details about the authentication servers, and ICAP header extensions that
might be present in REQMOD and RESPMOD requests, such as X-Authenticated-User and
X-Authenticated-Groups, to provide information about the source of the encapsulated HTTP message.
Web | Web Configuration | ICAP | Authentication
Using this information, the appliance can identify the user's name for its user-based policies and URL
filtering reports, without the need to configure authentication services or authentication groups on the
appliance. The appliance can extract the user name and group names from the ICAP header
extensions. The appliance does not authenticate users. Authentication is done by another server (for
example, a web-caching appliance). However, if the appliance can extract the user's identity, it can
apply URL filtering and other policy settings based on that identity.
Table 157 Option definitions
Option
Definition
Authenticated user
Specifies a header that the ICAP server adds after it has authenticated the user
to show who made the request.
header
Default value is X-Authenticated-User.
Specifies the user name. Typically this is in plain text or by default, base 64.
Authenticated user
encoding
Authenticated user
Specifies a regular expression that enables the appliance to extract the user
pattern
name from the text of the Authenticated user header.
Default value is ^(?:.*/)?(?:([^=]*)|.*cn=([^\s,=]+).*)$
Specifies a header that the ICAP server adds after it has authenticated the group
Authenticated group
header
to show who made the request.
Default value is X-Authenticated-User-Group.
Authenticated group
Specifies the group name. Typically this is in plain text or by default, Base 64.
encoding
Specifies a regular expression that enables the appliance to extract the group
Authenticated group
name from the text of the Authenticated groups header.
pattern
Default value is ^(?:.*/)?(?:([^=]*)|.*ou=([^\s,=]+).*)$
Definition
Default value is /RESPMOD.
McAfee Email and Web Security Appliances 5.6.0 Product Guide
Overview of Web features
Web Configuration
171

Advertisement

Table of Contents
loading

This manual is also suitable for:

Web security appliance 5.6.0

Table of Contents