McAfee MAP-3300-SWG Product Guide - Page 173

Enable data trickling, Data trickling, during data receipt, Denied Verbs, Permitted, Verbs, Denied

Page 173 highlights

Overview of Web features Web Configuration Data trickling (response modification only) Table 160 Option definitions Option Enable data trickling Data trickling Definition Enables the downloading of large files to the client before the whole file has been received from the server. Caution: Data trickling can leave your network vulnerable to viruses and other potentially harmful software because the file is not fully scanned. For this reason, we do not recommend data trickling. Default values are: Delay before data trickling starts - 15 seconds Trickle data every - 10 seconds Amount of data to trickle each time - 1024 bytes Maximum amount of data to trickle - 10% Enable data trickling during data receipt When selected, enables data trickling during data receipt. This is an advanced feature for NetCache clients only, Permissions (request modification only) Table 161 Option definitions Option Denied Verbs Permitted Verbs Denied Schemes Definition Displays the HTTP verbs that cannot be used in the communication between the ICAP client and the appliance when the ICAP client uses the REQMOD option. When you add any HTTP verbs to this list, by implication, you permit the use of all other verbs that are not in that list. Displays the HTTP verbs that can be used in the communication between the ICAP client and the appliance when the ICAP client uses the REQMOD option. When you add any HTTP verbs to this list, by implication, you deny all other verbs that are not in that list. Displays the request schemes that cannot be used. URLs include text that defines which resource is being requested. After you add any schemes to this list, by implication, you permit the use of all other schemes that are not in the list. Permitted Schemes Displays the request schemes that can be used. URLs include text that defines which resource is being requested. After you add any schemes to this list, by implication, you deny the use of all other schemes that are not in this list. Permitted Ports Displays the HTTP port numbers that the appliance will use when forwarding traffic. For security reasons, the appliance forwards requests only to certain port numbers, which prevents hackers tunnelling different protocols over a HTTP connection. Use this option for HTTP traffic that is not sent over the SSL. The entry 1025- means port number 1025 or above. Permitted SSL Ports Displays the HTTP port numbers that the appliance will use when forwarding traffic over SSL (Secure Socket Layer). For security reasons, the appliance forwards requests only to certain port numbers, which prevents hackers tunnelling different protocols over a HTTP connection. The port numbers that can be used depend on the HTTP verb. Access using the CONNECT verb is most tightly restricted, because once this verb has been accepted, there is little restriction on the data that can be transferred. Web browsers configured to operate in proxy mode use the CONNECT verb when trying to initiate a HTTPS connection running over SSL. The entry 1025- means port number 1025 or above. Typical values are 443 (HTTPS) and 563 (SNEWS). McAfee Email and Web Security Appliances 5.6.0 Product Guide 173

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Data trickling (response modification only)
Table 160
Option definitions
Option
Definition
Enable data trickling
Enables the downloading of large files to the client before the whole file has been
received from the server. Caution: Data trickling can leave your network
vulnerable to viruses and other potentially harmful software because the file is
not fully scanned. For this reason, we do not recommend data trickling.
Data trickling
Default values are:
Delay before data trickling starts — 15 seconds
Trickle data every — 10 seconds
Amount of data to trickle each time — 1024 bytes
Maximum amount of data to trickle — 10%
Enable data trickling
during data receipt
When selected, enables data trickling during data receipt.
This is an advanced feature for NetCache clients only,
Permissions (request modification only)
Table 161
Option definitions
Option
Definition
Denied Verbs
Displays the HTTP verbs that cannot be used in the communication between the ICAP
client and the appliance when the ICAP client uses the REQMOD option. When you add
any HTTP verbs to this list, by implication, you permit the use of all other verbs that are
not in that list.
Permitted
Verbs
Displays the HTTP verbs that can be used in the communication between the ICAP client
and the appliance when the ICAP client uses the REQMOD option. When you add any
HTTP verbs to this list, by implication, you deny all other verbs that are not in that list.
Denied
Schemes
Displays the request schemes that cannot be used. URLs include text that defines which
resource is being requested.
After you add any schemes to this list, by implication, you permit the use of all other
schemes that are not in the list.
Permitted
Schemes
Displays the request schemes that can be used. URLs include text that defines which
resource is being requested.
After you add any schemes to this list, by implication, you deny the use of all other
schemes that are not in this list.
Permitted
Ports
Displays the HTTP port numbers that the appliance will use when forwarding traffic. For
security reasons, the appliance forwards requests only to certain port numbers, which
prevents hackers tunnelling different protocols over a HTTP connection. Use this option
for HTTP traffic that is not sent over the SSL.
The entry 1025- means port number 1025 or above.
Permitted SSL
Ports
Displays the HTTP port numbers that the appliance will use when forwarding traffic over
SSL (Secure Socket Layer). For security reasons, the appliance forwards requests only
to certain port numbers, which prevents hackers tunnelling different protocols over a
HTTP connection.
The port numbers that can be used depend on the HTTP verb. Access using the
CONNECT verb is most tightly restricted, because once this verb has been accepted,
there is little restriction on the data that can be transferred. Web browsers configured to
operate in proxy mode use the CONNECT verb when trying to initiate a HTTPS
connection running over SSL.
The entry 1025- means port number 1025 or above.
Typical values are 443 (HTTPS) and 563 (SNEWS).
Overview of Web features
Web Configuration
McAfee Email and Web Security Appliances 5.6.0 Product Guide
173